wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.
We have discovered 581,832 live websites that are affected by CVE-2017-17093.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 581,832 live websites (7.09% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 831 versions ( 63% of all versions) |
| 102,936 websites | |
| 76,966 websites | |
| 44,543 websites | |
| 36,928 websites | |
| 30,947 websites | |
| 27,660 websites | |
| 26,955 websites | |
| 25,432 websites | |
| 16,224 websites | |
| 13,526 websites |
| .com | 208,651 websites |
| .it | 50,607 websites |
| .ru | 25,787 websites |
| .de | 21,664 websites |
| .org | 21,020 websites |
| .pl | 18,439 websites |
| .net | 17,448 websites |
| .co.uk | 15,211 websites |
| .nl | 11,680 websites |
| .fr | 10,559 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.br | *** | ||
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| ******.com | *,*** | ||
| ***********.eu | *,*** | ||
| *****.****.br | *,*** | ||
| *******.org | *,*** | ||
| ********.****.br | *,*** | ||
| *********.io | *,*** | ||
| ***********.com | *,*** |