CVE-2017-5492

Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets.php.


We have discovered 531,221 live websites that are affected by CVE-2017-5492.

Test my site




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains531,221 live websites (5.76% of WordPress install base)
Vulnerable Versions
  • from 0 before 4.7.1
Vulnerable Versions Count591 versions ( 63.48% of all versions)



Details

  • Published - Jan 15, 2017
  • Updated - Aug 5, 2024

CVE-2017-5492 usage by Country

United States95,611 websites



Italy74,227 websites
Germany37,398 websites
Japan30,741 websites
Australia29,203 websites
GB25,973 websites
France23,904 websites
Russia22,177 websites
Poland19,695 websites
Netherlands18,290 websites

CVE-2017-5492 usage by TLD

.com185,473 websites
.it49,355 websites
.com.au20,861 websites
.ru19,488 websites
.org17,905 websites
.de17,540 websites
.net16,524 websites
.co.uk15,838 websites
.pl14,272 websites
.nl12,268 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2017-5492

Top websites that are affected by CVE-2017-5492. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com United States*,***
****.***********.de Germany*,***
*************.com United States*,***
************.org United States*,***
********.eu Austria*,***
********************.ru Russia*,***
*******.**.ca Canada*,***
**********.com United States**,***
***************.org United States**,***
**************.********.com United States**,***
See full domain list

FAQ

A total of 531,221 websites have been identified as vulnerable to CVE-2017-5492, discovered through global website indexing conducted by WebTechSurvey.
WordPress is susceptible to CVE-2017-5492 vulnerability.
WordPress versions before 4.7.1 are vulnerable to CVE-2017-5492.
Version 4.7.1 of WordPress addresses the CVE-2017-5492 security vulnerability.