Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.
We have discovered 375,376 live websites that are affected by CVE-2016-7168.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 375,376 live websites (4.63% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 279 versions ( 42% of all versions) |
| 55,582 websites | |
| 62,710 websites | |
| 28,058 websites | |
| 20,788 websites | |
| 20,600 websites | |
| 19,994 websites | |
| 17,786 websites | |
| 15,324 websites | |
| 12,219 websites | |
| 8,584 websites |
| .com | 125,005 websites |
| .it | 40,569 websites |
| .ru | 17,433 websites |
| .pl | 12,629 websites |
| .org | 12,529 websites |
| .de | 12,355 websites |
| .net | 11,294 websites |
| .co.uk | 10,839 websites |
| .nl | 7,530 websites |
| .fr | 5,720 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| ********.eu | *,*** | ||
| ********************.ru | *,*** | ||
| ********************.com | *,*** | ||
| *******.**.ca | *,*** | ||
| **********.com | **,*** | ||
| *****.com | **,*** | ||
| ***********.**.za | **,*** | ||
| **************.se | **,*** |