CVE-2017-5611

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.


We have discovered 531,835 live websites that are affected by CVE-2017-5611.

Test my site




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains531,835 live websites (5.77% of WordPress install base)
Vulnerable Versions
  • from 0 before 4.7.2
Vulnerable Versions Count592 versions ( 63.59% of all versions)



Details

  • Published - Jan 30, 2017
  • Updated - Aug 5, 2024

CVE-2017-5611 usage by Country

United States95,809 websites



Italy74,240 websites
Germany37,461 websites
Japan30,793 websites
Australia29,207 websites
GB25,992 websites
France23,931 websites
Russia22,204 websites
Poland19,714 websites
Netherlands18,309 websites

CVE-2017-5611 usage by TLD

.com185,715 websites
.it49,367 websites
.com.au20,865 websites
.ru19,508 websites
.org17,928 websites
.de17,575 websites
.net16,545 websites
.co.uk15,856 websites
.pl14,286 websites
.nl12,285 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2017-5611

Top websites that are affected by CVE-2017-5611. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com United States*,***
****.***********.de Germany*,***
*************.com United States*,***
************.org United States*,***
********.eu Austria*,***
********************.ru Russia*,***
*******.**.ca Canada*,***
**********.com United States**,***
***************.org United States**,***
**************.********.com United States**,***
See full domain list

FAQ

A total of 531,835 websites have been identified as vulnerable to CVE-2017-5611, discovered through global website indexing conducted by WebTechSurvey.
WordPress is susceptible to CVE-2017-5611 vulnerability.
WordPress versions before 4.7.2 are vulnerable to CVE-2017-5611.
Version 4.7.2 of WordPress addresses the CVE-2017-5611 security vulnerability.