WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
We have discovered 509,485 live websites that are affected by CVE-2017-16510.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 509,485 live websites (5.86% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 344 versions ( 52% of all versions) |
| 88,513 websites | |
| 69,383 websites | |
| 38,513 websites | |
| 37,511 websites | |
| 27,189 websites | |
| 24,254 websites | |
| 23,886 websites | |
| 20,557 websites | |
| 16,356 websites | |
| 10,939 websites |
| .com | 182,322 websites |
| .it | 45,127 websites |
| .ru | 22,751 websites |
| .de | 18,734 websites |
| .org | 18,155 websites |
| .net | 17,035 websites |
| .pl | 14,777 websites |
| .co.uk | 13,845 websites |
| .nl | 12,014 websites |
| .fr | 8,706 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.br | *** | ||
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| *****.****.br | *,*** | ||
| ********.****.br | *,*** | ||
| ********.eu | *,*** | ||
| ********************.ru | *,*** | ||
| *****************.****.br | *,*** | ||
| ****************.com | *,*** | ||
| *******.**.ca | *,*** |