Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.
We have discovered 488,669 live websites that are affected by CVE-2016-7168.
Product | |
Category | Content Management System |
Vulnerable Domains | 488,669 live websites (5.30% of WordPress install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 555 versions ( 59.61% of all versions) |
![]() | 82,030 websites |
![]() | 72,994 websites |
![]() | 33,890 websites |
![]() | 28,525 websites |
![]() | 26,288 websites |
![]() | 24,577 websites |
![]() | 21,308 websites |
![]() | 20,421 websites |
![]() | 18,390 websites |
![]() | 17,369 websites |
.com | 166,195 websites |
.it | 48,430 websites |
.com.au | 20,216 websites |
.ru | 17,953 websites |
.org | 16,372 websites |
.de | 15,858 websites |
.net | 14,936 websites |
.co.uk | 14,804 websites |
.pl | 13,289 websites |
.nl | 11,533 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.com | ![]() | *,*** | |
****.***********.de | ![]() | *,*** | |
*************.com | ![]() | *,*** | |
************.org | ![]() | *,*** | |
********.eu | ![]() | *,*** | |
********************.ru | ![]() | *,*** | |
*******.**.ca | ![]() | *,*** | |
**********.com | ![]() | **,*** | |
**************.********.com | ![]() | **,*** | |
***********.com | ![]() | **,*** |
FAQ