wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.
We have discovered 442,792 live websites that are affected by CVE-2017-5610.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 442,792 live websites (5.40% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 768 versions ( 58% of all versions) |
| 74,369 websites | |
| 69,276 websites | |
| 32,637 websites | |
| 24,511 websites | |
| 23,149 websites | |
| 22,394 websites | |
| 20,990 websites | |
| 18,996 websites | |
| 13,027 websites | |
| 12,629 websites |
| .com | 153,862 websites |
| .it | 45,478 websites |
| .ru | 18,594 websites |
| .org | 15,893 websites |
| .de | 15,757 websites |
| .pl | 15,066 websites |
| .net | 12,817 websites |
| .co.uk | 12,486 websites |
| .nl | 8,861 websites |
| .fr | 7,623 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| ******.com | *,*** | ||
| ***********.eu | *,*** | ||
| *******.org | *,*** | ||
| *********.io | *,*** | ||
| ***********.com | *,*** | ||
| ********.com | *,*** | ||
| ********.org | *,*** | ||
| ********.eu | *,*** |