The ShopBuilder WordPress plugin before 3.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
We have discovered 396 live websites that are affected by CVE-2025-13456.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 396 live websites (86% of Shopbuilder install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 32 versions ( 94% of all versions) |
| 108 websites | |
| 32 websites | |
| 20 websites | |
| 20 websites | |
| 17 websites | |
| 14 websites | |
| 13 websites | |
| 10 websites | |
| 10 websites | |
| 10 websites |
| .com | 183 websites |
| .it | 11 websites |
| .co.uk | 11 websites |
| .org | 11 websites |
| .pl | 10 websites |
| .com.br | 8 websites |
| .nl | 8 websites |
| .com.au | 7 websites |
| .ca | 5 websites |
| .fr | 5 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.stream | *,***,*** | ||
| *******.pl | *,***,*** | ||
| ********************.nl | *,***,*** | ||
| ****************.pl | *,***,*** | ||
| ***************.**.uk | *,***,*** | ||
| ********.se | *,***,*** | ||
| ************.com | *,***,*** | ||
| *******.com | *,***,*** | ||
| ***************.com | *,***,*** | ||
| *****.pl | *,***,*** |
FAQ