Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.
We have discovered 337,226 live websites that are affected by CVE-2016-6897.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 337,226 live websites (4.22% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 846 versions ( 57% of all versions) |
| 65,890 websites | |
| 47,496 websites | |
| 28,751 websites | |
| 23,665 websites | |
| 16,540 websites | |
| 14,593 websites | |
| 13,404 websites | |
| 10,545 websites | |
| 7,049 websites | |
| 6,629 websites |
| .com | 121,832 websites |
| .it | 31,710 websites |
| .ru | 13,772 websites |
| .org | 12,724 websites |
| .de | 12,494 websites |
| .net | 10,792 websites |
| .nl | 8,462 websites |
| .co.uk | 7,690 websites |
| .jp | 6,942 websites |
| .fr | 6,088 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *,*** | ||
| *****.com | *,*** | ||
| ********.com | *,*** | ||
| ************.org | *,*** | ||
| ******.com | *,*** | ||
| *******.org | *,*** | ||
| *********.io | *,*** | ||
| *******.com | *,*** | ||
| ********.eu | *,*** | ||
| *************.org | *,*** |