CVE-2023-6782

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 11,872 live websites that are affected by CVE-2023-6782.

Test my site




Affected Software

Product  AMP for WP
Category Wordpress Plugins
Vulnerable Domains11,872 live websites (26.17% of AMP for WP install base)
Vulnerable Versions
  • from 0 through 1.0.92
Vulnerable Versions Count230 versions ( 93.50% of all versions)



Details

  • Published - Jan 11, 2024
  • Updated - Aug 2, 2024

Credits

  • Ngô Thiên An (finder)

CVE-2023-6782 usage by Country

United States5,793 websites



Germany1,674 websites
Russia768 websites
France623 websites
Japan384 websites
Spain193 websites
GB179 websites
Vietnam162 websites
Brazil153 websites
Italy153 websites

CVE-2023-6782 usage by TLD

.com5,888 websites
.ru955 websites
.net563 websites
.org457 websites
.com.br239 websites
.info213 websites
.fr183 websites
.it165 websites
.de139 websites
.pl108 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-6782

Top websites that are affected by CVE-2023-6782. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.de Germany**,***
**********.ir Iran**,***
***.********.com United States**,***
*******.de France**,***
******.***.br United States**,***
**********.***.pk Pakistan**,***
*****************.com United States**,***
**********.com United States**,***
**********.fr France**,***
********.com United States**,***
See full domain list

FAQ

A total of 11,872 websites have been identified as vulnerable to CVE-2023-6782, discovered through global website indexing conducted by WebTechSurvey.
AMP for WP is susceptible to CVE-2023-6782 vulnerability.
AMP for WP versions before, and including, 1.0.92 are vulnerable to CVE-2023-6782.