CVE-2023-7200


EventON < 4.4.1 - Reflected Cross-Site Scripting

The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin



We have discovered 13,033 live websites that are affected by CVE-2023-7200.

Contact us to get more info




Affected Software

Product  EventOn
Category Appointment Scheduling
Vulnerable Versions
  • from 0 before 4.4.1
Total Vulnerable Versions194
Vulnerable Domains13,033 live websites (78.61% of EventOn install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-7200 and the relative popularity of websites


Details

  • Published - Jan 29, 2024
  • Updated - Jan 29, 2024

Credits

  • kauenavarro (finder)
  • WPScan (coordinator)





Countries

United States4,150 websites



Germany1,267 websites
France1,038 websites
Italy660 websites
Spain655 websites
GB629 websites
Netherlands486 websites
Canada431 websites
Brazil291 websites
Australia266 websites

TLDs

.com4,592 websites
.org1,708 websites
.de865 websites
.it441 websites
.fr436 websites
.nl411 websites
.co.uk321 websites
.net247 websites
.es245 websites
.ch205 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-7200 through included software libraries and plugins.



References


Websites affected by CVE-2023-7200

Top websites that are affected by CVE-2023-7200. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*************.pl Poland**,***
*********************.org United States**,***
*****************.hr Croatia**,***
****.hr Croatia**,***
***.*******.org United States**,***
***.org United States**,***
*****.gov United States**,***
***.************.org United States**,***
***.***.org France**,***
*****.***.uk GB**,***
See full domain list