wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.
We have discovered 414,394 live websites that are affected by CVE-2017-5493.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 414,394 live websites (4.99% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 310 versions ( 47% of all versions) |
| 63,556 websites | |
| 66,769 websites | |
| 30,494 websites | |
| 25,061 websites | |
| 22,724 websites | |
| 21,483 websites | |
| 18,793 websites | |
| 17,698 websites | |
| 14,052 websites | |
| 8,182 websites |
| .com | 139,537 websites |
| .it | 43,273 websites |
| .ru | 19,041 websites |
| .org | 14,094 websites |
| .de | 13,840 websites |
| .pl | 13,350 websites |
| .net | 12,928 websites |
| .co.uk | 12,002 websites |
| .nl | 9,007 websites |
| .fr | 6,500 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| ********.eu | *,*** | ||
| ********************.ru | *,*** | ||
| ********************.com | *,*** | ||
| *******.**.ca | *,*** | ||
| **********.com | **,*** | ||
| ***************.org | **,*** | ||
| *****.com | **,*** | ||
| *******.com | **,*** |