CVE-2017-5493

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.


We have discovered 414,394 live websites that are affected by CVE-2017-5493.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains414,394 live websites (4.99% of WordPress install base)
Vulnerable Versions
  • from 0 through 4.7.1
Vulnerable Versions Count310 versions ( 47% of all versions)



Details

  • Published - Jan 15, 2017
  • Updated - Aug 5, 2024

Website Distribution by Country

Number of websites using CVE-2017-5493
United States63,556 websites



Italy66,769 websites
Germany30,494 websites
Japan25,061 websites
Russia22,724 websites
GB21,483 websites
Poland18,793 websites
France17,698 websites
Netherlands14,052 websites
Iran8,182 websites

Website Distribution by TLD

Number of websites using CVE-2017-5493
.com139,537 websites
.it43,273 websites
.ru19,041 websites
.org14,094 websites
.de13,840 websites
.pl13,350 websites
.net12,928 websites
.co.uk12,002 websites
.nl9,007 websites
.fr6,500 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2017-5493

Top websites that are affected by CVE-2017-5493. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com United States*,***
************.org United States*,***
********.eu Austria*,***
********************.ru Russia*,***
********************.com Cyprus*,***
*******.**.ca Canada*,***
**********.com United States**,***
***************.org United States**,***
*****.com Italy**,***
*******.com United States**,***
See full domain list

FAQ

A total of 414,394 websites have been identified as vulnerable to CVE-2017-5493, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2017-5493 vulnerability.
WordPress versions up to and including 4.7.1 are vulnerable to CVE-2017-5493.