CVE-2016-7168

Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.


We have discovered 375,376 live websites that are affected by CVE-2016-7168.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains375,376 live websites (4.63% of WordPress install base)
Vulnerable Versions
  • from 0 through 4.6.1
Vulnerable Versions Count279 versions ( 42% of all versions)



Details

  • Published - Jan 5, 2017
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2016-7168
United States55,582 websites



Italy62,710 websites
Germany28,058 websites
Russia20,788 websites
Japan20,600 websites
GB19,994 websites
Poland17,786 websites
France15,324 websites
Netherlands12,219 websites
Iran8,584 websites

Website Distribution by TLD

Number of websites using CVE-2016-7168
.com125,005 websites
.it40,569 websites
.ru17,433 websites
.pl12,629 websites
.org12,529 websites
.de12,355 websites
.net11,294 websites
.co.uk10,839 websites
.nl7,530 websites
.fr5,720 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2016-7168

Top websites that are affected by CVE-2016-7168. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com United States*,***
************.org United States*,***
********.eu Austria*,***
********************.ru Russia*,***
********************.com Cyprus*,***
*******.**.ca Canada*,***
**********.com United States**,***
*****.com Italy**,***
***********.**.za South Africa**,***
**************.se Sweden**,***
See full domain list

FAQ

A total of 375,376 websites have been identified as vulnerable to CVE-2016-7168, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2016-7168 vulnerability.
WordPress versions up to and including 4.6.1 are vulnerable to CVE-2016-7168.