Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.
We have discovered 388,730 live websites that are affected by CVE-2016-7169.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 388,730 live websites (4.68% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 279 versions ( 42% of all versions) |
| 58,148 websites | |
| 64,986 websites | |
| 28,187 websites | |
| 22,579 websites | |
| 21,405 websites | |
| 20,509 websites | |
| 17,959 websites | |
| 16,001 websites | |
| 13,411 websites | |
| 8,006 websites |
| .com | 129,344 websites |
| .it | 42,109 websites |
| .ru | 17,994 websites |
| .org | 13,224 websites |
| .pl | 12,761 websites |
| .de | 12,661 websites |
| .net | 12,033 websites |
| .co.uk | 11,345 websites |
| .nl | 8,513 websites |
| .fr | 5,833 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| ********.eu | *,*** | ||
| ********************.ru | *,*** | ||
| ********************.com | *,*** | ||
| *******.**.ca | *,*** | ||
| **********.com | **,*** | ||
| *****.com | **,*** | ||
| ***********.**.za | **,*** | ||
| **************.se | **,*** |