CVE-2013-0236

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.


We have discovered 231,436 live websites that are affected by CVE-2013-0236.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains231,436 live websites (2.82% of WordPress install base)
Vulnerable Versions
  • from 0 through 3.5.1
Vulnerable Versions Count351 versions ( 27% of all versions)



Details

  • Published - Jul 8, 2013
  • Updated - Sep 16, 2024

Website Distribution by Country

Number of websites using CVE-2013-0236
United States22,340 websites



Italy56,620 websites
GB15,246 websites
Poland15,102 websites
Germany13,410 websites
Iran12,485 websites
Russia12,119 websites
Kazakhstan7,244 websites
Netherlands6,731 websites
South Africa5,979 websites

Website Distribution by TLD

Number of websites using CVE-2013-0236
.com66,880 websites
.it37,160 websites
.pl10,758 websites
.ru10,073 websites
.co.uk7,711 websites
.org6,745 websites
.net5,620 websites
.de5,199 websites
.nl4,082 websites
.se3,651 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2013-0236

Top websites that are affected by CVE-2013-0236. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com United States*,***
************.org United States*,***
***********.eu Cyprus*,***
*******.org United States*,***
********************.ru Russia*,***
*******.**.ca Canada*,***
*********.org United States**,***
*****.com Italy**,***
***********.**.za South Africa**,***
**************.se Sweden**,***
See full domain list

FAQ

A total of 231,436 websites have been identified as vulnerable to CVE-2013-0236, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2013-0236 vulnerability.
WordPress versions up to and including 3.5.1 are vulnerable to CVE-2013-0236.