CVE-2017-17091

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.


We have discovered 501,741 live websites that are affected by CVE-2017-17091.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains501,741 live websites (6.28% of WordPress install base)
Vulnerable Versions
  • from 0 through 4.9.1
Vulnerable Versions Count945 versions ( 63% of all versions)



Details

  • Published - Dec 2, 2017
  • Updated - Aug 5, 2024

Website Distribution by Country

Number of websites using CVE-2017-17091
United States100,084 websites



Italy56,569 websites
Japan48,086 websites
Germany37,232 websites
Russia25,799 websites
France23,617 websites
GB18,906 websites
Netherlands14,547 websites
Poland11,694 websites
Spain10,666 websites

Website Distribution by TLD

Number of websites using CVE-2017-17091
.com187,581 websites
.it37,789 websites
.ru21,565 websites
.de19,370 websites
.org18,777 websites
.net16,647 websites
.nl11,663 websites
.jp11,337 websites
.co.uk11,072 websites
.fr9,446 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2017-17091

Top websites that are affected by CVE-2017-17091. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.br Brazil***
*******.com United States*,***
*****.com United States*,***
********.com United States*,***
************.org United States*,***
******.com France*,***
*****.****.br Brazil*,***
*******.org United States*,***
********.****.br Brazil*,***
*********.io Netherlands*,***
See full domain list

FAQ

A total of 501,741 websites have been identified as vulnerable to CVE-2017-17091, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2017-17091 vulnerability.
WordPress versions up to and including 4.9.1 are vulnerable to CVE-2017-17091.