In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.
We have discovered 448,247 live websites that are affected by CVE-2017-6814.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 448,247 live websites (5.46% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 769 versions ( 58% of all versions) |
| 75,777 websites | |
| 69,497 websites | |
| 32,915 websites | |
| 24,795 websites | |
| 23,297 websites | |
| 22,541 websites | |
| 21,114 websites | |
| 19,131 websites | |
| 13,033 websites | |
| 12,715 websites |
| .com | 156,993 websites |
| .it | 45,590 websites |
| .ru | 18,721 websites |
| .org | 16,162 websites |
| .de | 15,911 websites |
| .pl | 15,162 websites |
| .net | 13,137 websites |
| .co.uk | 12,579 websites |
| .nl | 8,934 websites |
| .fr | 7,670 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| ******.com | *,*** | ||
| ***********.eu | *,*** | ||
| *******.org | *,*** | ||
| *********.io | *,*** | ||
| ***********.com | *,*** | ||
| ********.com | *,*** | ||
| ********.org | *,*** | ||
| ********.eu | *,*** |