Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets.php.
We have discovered 531,221 live websites that are affected by CVE-2017-5492.
Product | |
Category | Content Management System |
Vulnerable Domains | 531,221 live websites (5.76% of WordPress install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 591 versions ( 63.48% of all versions) |
![]() | 95,611 websites |
![]() | 74,227 websites |
![]() | 37,398 websites |
![]() | 30,741 websites |
![]() | 29,203 websites |
![]() | 25,973 websites |
![]() | 23,904 websites |
![]() | 22,177 websites |
![]() | 19,695 websites |
![]() | 18,290 websites |
.com | 185,473 websites |
.it | 49,355 websites |
.com.au | 20,861 websites |
.ru | 19,488 websites |
.org | 17,905 websites |
.de | 17,540 websites |
.net | 16,524 websites |
.co.uk | 15,838 websites |
.pl | 14,272 websites |
.nl | 12,268 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.com | ![]() | *,*** | |
****.***********.de | ![]() | *,*** | |
*************.com | ![]() | *,*** | |
************.org | ![]() | *,*** | |
********.eu | ![]() | *,*** | |
********************.ru | ![]() | *,*** | |
*******.**.ca | ![]() | *,*** | |
**********.com | ![]() | **,*** | |
***************.org | ![]() | **,*** | |
**************.********.com | ![]() | **,*** |
FAQ