CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.


We have discovered 509,485 live websites that are affected by CVE-2017-16510.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains509,485 live websites (5.86% of WordPress install base)
Vulnerable Versions
  • from 0 through 4.8.3
Vulnerable Versions Count344 versions ( 52% of all versions)



Details

  • Published - Nov 2, 2017
  • Updated - Aug 5, 2024

Website Distribution by Country

Number of websites using CVE-2017-16510
United States88,513 websites



Italy69,383 websites
Germany38,513 websites
Japan37,511 websites
Russia27,189 websites
GB24,254 websites
France23,886 websites
Poland20,557 websites
Netherlands16,356 websites
Australia10,939 websites

Website Distribution by TLD

Number of websites using CVE-2017-16510
.com182,322 websites
.it45,127 websites
.ru22,751 websites
.de18,734 websites
.org18,155 websites
.net17,035 websites
.pl14,777 websites
.co.uk13,845 websites
.nl12,014 websites
.fr8,706 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2017-16510

Top websites that are affected by CVE-2017-16510. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.br Brazil***
*****.com United States*,***
************.org United States*,***
*****.****.br Brazil*,***
********.****.br Brazil*,***
********.eu Austria*,***
********************.ru Russia*,***
*****************.****.br Brazil*,***
****************.com United States*,***
*******.**.ca Canada*,***
See full domain list

FAQ

A total of 509,485 websites have been identified as vulnerable to CVE-2017-16510, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2017-16510 vulnerability.
WordPress versions up to and including 4.8.3 are vulnerable to CVE-2017-16510.