CVE-2016-7168

Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.


We have discovered 488,669 live websites that are affected by CVE-2016-7168.

Test my site




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains488,669 live websites (5.30% of WordPress install base)
Vulnerable Versions
  • from 0 before 4.6.1
Vulnerable Versions Count555 versions ( 59.61% of all versions)



Details

  • Published - Jan 5, 2017
  • Updated - Aug 6, 2024

CVE-2016-7168 usage by Country

United States82,030 websites



Italy72,994 websites
Germany33,890 websites
Australia28,525 websites
Japan26,288 websites
GB24,577 websites
France21,308 websites
Russia20,421 websites
Poland18,390 websites
Netherlands17,369 websites

CVE-2016-7168 usage by TLD

.com166,195 websites
.it48,430 websites
.com.au20,216 websites
.ru17,953 websites
.org16,372 websites
.de15,858 websites
.net14,936 websites
.co.uk14,804 websites
.pl13,289 websites
.nl11,533 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2016-7168

Top websites that are affected by CVE-2016-7168. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com United States*,***
****.***********.de Germany*,***
*************.com United States*,***
************.org United States*,***
********.eu Austria*,***
********************.ru Russia*,***
*******.**.ca Canada*,***
**********.com United States**,***
**************.********.com United States**,***
***********.com Italy**,***
See full domain list

FAQ

A total of 488,669 websites have been identified as vulnerable to CVE-2016-7168, discovered through global website indexing conducted by WebTechSurvey.
WordPress is susceptible to CVE-2016-7168 vulnerability.
WordPress versions before 4.6.1 are vulnerable to CVE-2016-7168.
Version 4.6.1 of WordPress addresses the CVE-2016-7168 security vulnerability.