CVE-2023-6941

Keap Official Opt-in Forms <= 1.0.11 - Admin+ Stored XSS

The Keap Official Opt-in Forms WordPress plugin through 1.0.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).


We have discovered 774 live websites that are affected by CVE-2023-6941.

Run a Free Instant Scan




Affected Software

Product  Infusionsoft Official Opt In Forms
Category Wordpress Plugins
Vulnerable Domains774 live websites (100% of Infusionsoft Official Opt In Forms install base)
Vulnerable Versions
  • from 0 through 1.0.11
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jan 15, 2024
  • Updated - Jun 20, 2025

Credits

  • MINGYOUNG BAN (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2023-6941
United States601 websites



GB50 websites
Canada28 websites
Australia27 websites
Germany12 websites
Italy7 websites
Bulgaria5 websites
Brazil5 websites
Singapore5 websites

Website Distribution by TLD

Number of websites using CVE-2023-6941
.com601 websites
.co.uk34 websites
.org30 websites
.com.au27 websites
.net22 websites
.ca11 websites
.it8 websites
.com.br5 websites
.ch2 websites
.es2 websites

Websites affected by CVE-2023-6941

Top websites that are affected by CVE-2023-6941. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com United States**,***
**************.com United States***,***
*********************.com United States***,***
*********.com United States***,***
***********.com United States***,***
*********************.org United States***,***
*************.com United States***,***
**************.org United States***,***
**************.com United States***,***
**********.com United States***,***
See full domain list

FAQ

CVE-2023-6941 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Infusionsoft Official Opt In Forms
A total of 774 websites have been identified as vulnerable to CVE-2023-6941, based on global website indexing conducted by WebTechSurvey.
The Infusionsoft Official Opt In Forms is affected by the CVE-2023-6941 vulnerability.
Infusionsoft Official Opt In Forms versions up to and including 1.0.11 are vulnerable to CVE-2023-6941.