Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.
We have discovered 350,163 live websites that are affected by CVE-2016-5833.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 350,163 live websites (4.03% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 247 versions ( 37% of all versions) |
| 54,287 websites | |
| 60,489 websites | |
| 24,658 websites | |
| 20,062 websites | |
| 18,604 websites | |
| 18,405 websites | |
| 15,624 websites | |
| 14,961 websites | |
| 12,381 websites | |
| 8,825 websites |
| .com | 117,523 websites |
| .it | 39,263 websites |
| .ru | 15,688 websites |
| .org | 12,365 websites |
| .de | 11,917 websites |
| .net | 11,127 websites |
| .pl | 11,113 websites |
| .co.uk | 9,998 websites |
| .nl | 8,930 websites |
| .com.au | 6,536 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| ********.eu | *,*** | ||
| ********************.ru | *,*** | ||
| *******.**.ca | *,*** | ||
| **********.com | **,*** | ||
| ***********.**.za | **,*** | ||
| **************.se | **,*** | ||
| ********.com | **,*** | ||
| ***************.com | **,*** |