CVE-2016-7169

Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.


We have discovered 388,730 live websites that are affected by CVE-2016-7169.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains388,730 live websites (4.68% of WordPress install base)
Vulnerable Versions
  • from 0 through 4.6.1
Vulnerable Versions Count279 versions ( 42% of all versions)



Details

  • Published - Jan 5, 2017
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2016-7169
United States58,148 websites



Italy64,986 websites
Germany28,187 websites
Japan22,579 websites
Russia21,405 websites
GB20,509 websites
Poland17,959 websites
France16,001 websites
Netherlands13,411 websites
Iran8,006 websites

Website Distribution by TLD

Number of websites using CVE-2016-7169
.com129,344 websites
.it42,109 websites
.ru17,994 websites
.org13,224 websites
.pl12,761 websites
.de12,661 websites
.net12,033 websites
.co.uk11,345 websites
.nl8,513 websites
.fr5,833 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2016-7169

Top websites that are affected by CVE-2016-7169. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com United States*,***
************.org United States*,***
********.eu Austria*,***
********************.ru Russia*,***
********************.com Cyprus*,***
*******.**.ca Canada*,***
**********.com United States**,***
*****.com Italy**,***
***********.**.za South Africa**,***
**************.se Sweden**,***
See full domain list

FAQ

A total of 388,730 websites have been identified as vulnerable to CVE-2016-7169, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2016-7169 vulnerability.
WordPress versions up to and including 4.6.1 are vulnerable to CVE-2016-7169.