CVE-2016-10112

Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.


We have discovered 22,458 live websites that are affected by CVE-2016-10112.

Test my site




Affected Software

Product  WooCommerce
Category Ecommerce
Vulnerable Domains22,458 live websites (1.50% of WooCommerce install base)
Vulnerable Versions
  • from 0 before 2.6.9
Vulnerable Versions Count136 versions ( 28.22% of all versions)



Details

  • Published - Jan 4, 2017
  • Updated - Aug 6, 2024

CVE-2016-10112 usage by Country

United States6,611 websites



Germany1,789 websites
Russia1,354 websites
France1,319 websites
GB949 websites
Italy752 websites
Vietnam687 websites
Spain642 websites
Australia621 websites
Netherlands573 websites

CVE-2016-10112 usage by TLD

.com10,005 websites
.ru1,113 websites
.co.uk700 websites
.de646 websites
.org585 websites
.it580 websites
.com.au531 websites
.net475 websites
.nl436 websites
.com.br419 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2016-10112

Top websites that are affected by CVE-2016-10112. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.com Singapore**,***
*********.com United States**,***
***********.com GB**,***
****.*************.com United States**,***
*******.****.es Spain**,***
******.com United States***,***
*************.com Germany***,***
********.com United States***,***
*******************.com United States***,***
*************.com United States***,***
See full domain list

FAQ

A total of 22,458 websites have been identified as vulnerable to CVE-2016-10112, discovered through global website indexing conducted by WebTechSurvey.
WooCommerce is susceptible to CVE-2016-10112 vulnerability.
WooCommerce versions before 2.6.9 are vulnerable to CVE-2016-10112.
Version 2.6.9 of WooCommerce addresses the CVE-2016-10112 security vulnerability.