Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.
We have discovered 231,436 live websites that are affected by CVE-2013-0236.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 231,436 live websites (2.82% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 351 versions ( 27% of all versions) |
| 22,340 websites | |
| 56,620 websites | |
| 15,246 websites | |
| 15,102 websites | |
| 13,410 websites | |
| 12,485 websites | |
| 12,119 websites | |
| 7,244 websites | |
| 6,731 websites | |
| 5,979 websites |
| .com | 66,880 websites |
| .it | 37,160 websites |
| .pl | 10,758 websites |
| .ru | 10,073 websites |
| .co.uk | 7,711 websites |
| .org | 6,745 websites |
| .net | 5,620 websites |
| .de | 5,199 websites |
| .nl | 4,082 websites |
| .se | 3,651 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| ***********.eu | *,*** | ||
| *******.org | *,*** | ||
| ********************.ru | *,*** | ||
| *******.**.ca | *,*** | ||
| *********.org | **,*** | ||
| *****.com | **,*** | ||
| ***********.**.za | **,*** | ||
| **************.se | **,*** |