Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.
We have discovered 22,458 live websites that are affected by CVE-2016-10112.
Product | ![]() |
Category | Ecommerce |
Vulnerable Domains | 22,458 live websites (1.50% of WooCommerce install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 136 versions ( 28.22% of all versions) |
![]() | 6,611 websites |
![]() | 1,789 websites |
![]() | 1,354 websites |
![]() | 1,319 websites |
![]() | 949 websites |
![]() | 752 websites |
![]() | 687 websites |
![]() | 642 websites |
![]() | 621 websites |
![]() | 573 websites |
.com | 10,005 websites |
.ru | 1,113 websites |
.co.uk | 700 websites |
.de | 646 websites |
.org | 585 websites |
.it | 580 websites |
.com.au | 531 websites |
.net | 475 websites |
.nl | 436 websites |
.com.br | 419 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**************.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
****.*************.com | ![]() | **,*** | |
*******.****.es | ![]() | **,*** | |
******.com | ![]() | ***,*** | |
*************.com | ![]() | ***,*** | |
********.com | ![]() | ***,*** | |
*******************.com | ![]() | ***,*** | |
*************.com | ![]() | ***,*** |
FAQ