This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on the 'place_id' attribute. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 7,813 live websites that are affected by CVE-2023-6884.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 7,813 live websites (38.14% of Google Reviews Widget install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 75 versions ( 74.26% of all versions) |
![]() | 2,904 websites |
![]() | 853 websites |
![]() | 698 websites |
![]() | 493 websites |
![]() | 280 websites |
![]() | 276 websites |
![]() | 248 websites |
![]() | 245 websites |
![]() | 207 websites |
![]() | 181 websites |
.com | 3,647 websites |
.co.uk | 507 websites |
.de | 414 websites |
.fr | 384 websites |
.com.au | 375 websites |
.nl | 315 websites |
.pl | 193 websites |
.it | 170 websites |
.es | 159 websites |
.ca | 150 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*******.nl | ![]() | **,*** | |
******.**.il | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
***********.com | ![]() | ***,*** | |
***********.ca | ![]() | ***,*** | |
*****************.de | ![]() | ***,*** | |
********.pl | ![]() | ***,*** | |
**********.se | ![]() | ***,*** | |
*****************.com | ![]() | ***,*** | |
***********.com | ![]() | ***,*** |
FAQ