CVE-2016-5833

Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.


We have discovered 350,163 live websites that are affected by CVE-2016-5833.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains350,163 live websites (4.03% of WordPress install base)
Vulnerable Versions
  • from 0 through 4.5.3
Vulnerable Versions Count247 versions ( 37% of all versions)



Details

  • Published - Jun 29, 2016
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2016-5833
United States54,287 websites



Italy60,489 websites
Germany24,658 websites
Japan20,062 websites
Russia18,604 websites
GB18,405 websites
Poland15,624 websites
France14,961 websites
Netherlands12,381 websites
Australia8,825 websites

Website Distribution by TLD

Number of websites using CVE-2016-5833
.com117,523 websites
.it39,263 websites
.ru15,688 websites
.org12,365 websites
.de11,917 websites
.net11,127 websites
.pl11,113 websites
.co.uk9,998 websites
.nl8,930 websites
.com.au6,536 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2016-5833

Top websites that are affected by CVE-2016-5833. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com United States*,***
************.org United States*,***
********.eu Austria*,***
********************.ru Russia*,***
*******.**.ca Canada*,***
**********.com United States**,***
***********.**.za South Africa**,***
**************.se Sweden**,***
********.com France**,***
***************.com Italy**,***
See full domain list

FAQ

A total of 350,163 websites have been identified as vulnerable to CVE-2016-5833, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2016-5833 vulnerability.
WordPress versions up to and including 4.5.3 are vulnerable to CVE-2016-5833.