CVE-2015-3438

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.


We have discovered 218,569 live websites that are affected by CVE-2015-3438.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains218,569 live websites (2.70% of WordPress install base)
Vulnerable Versions
  • from 0 through 4.1.2
Vulnerable Versions Count632 versions ( 43% of all versions)



Details

  • Published - Aug 5, 2015
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2015-3438
United States38,909 websites



Italy35,800 websites
Japan16,143 websites
Germany14,211 websites
Russia12,766 websites
GB9,176 websites
France8,098 websites
Netherlands7,117 websites
Kazakhstan6,514 websites
South Africa5,173 websites

Website Distribution by TLD

Number of websites using CVE-2015-3438
.com73,731 websites
.it23,902 websites
.ru10,646 websites
.org8,017 websites
.de7,321 websites
.net6,644 websites
.nl5,597 websites
.co.uk5,122 websites
.jp4,118 websites
.se3,867 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2015-3438

Top websites that are affected by CVE-2015-3438. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States*,***
*****.com United States*,***
************.org United States*,***
*******.org United States*,***
*********.io Netherlands*,***
***********.com United States*,***
*******.com United States*,***
*************.com United States*,***
********************.ru Russia*,***
*******.**.ca Canada*,***
See full domain list

FAQ

A total of 218,569 websites have been identified as vulnerable to CVE-2015-3438, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2015-3438 vulnerability.
WordPress versions up to and including 4.1.2 are vulnerable to CVE-2015-3438.