The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from the `pager ` parameter. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the WP_Theme() class to create backdoors.
We have discovered 117 live websites that are affected by CVE-2017-20207.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 117 live websites (100% of Flickr Gallery install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 46 websites | |
| 16 websites | |
| 10 websites | |
| 6 websites | |
| 5 websites | |
| 4 websites | |
| 4 websites | |
| 4 websites | |
| 3 websites | |
| 2 websites |
| .com | 55 websites |
| .net | 10 websites |
| .de | 10 websites |
| .org | 6 websites |
| .co.uk | 6 websites |
| .it | 4 websites |
| .at | 2 websites |
| .nl | 2 websites |
| .ca | 2 websites |
| .ru | 2 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.info | ***,*** | ||
| ******************.com | ***,*** | ||
| *******.com | *,***,*** | ||
| *******************.com | *,***,*** | ||
| ****************.org | *,***,*** | ||
| **************.it | *,***,*** | ||
| ********.com | *,***,*** | ||
| ******.com | *,***,*** | ||
| ***********.com | *,***,*** | ||
| ********.***.uk | *,***,*** |
FAQ