CVE-2017-6814

In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.


We have discovered 448,247 live websites that are affected by CVE-2017-6814.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains448,247 live websites (5.46% of WordPress install base)
Vulnerable Versions
  • from 0 through 4.7.3
Vulnerable Versions Count769 versions ( 58% of all versions)



Details

  • Published - Mar 12, 2017
  • Updated - Aug 5, 2024

Website Distribution by Country

Number of websites using CVE-2017-6814
United States75,777 websites



Italy69,497 websites
Germany32,915 websites
Japan24,795 websites
GB23,297 websites
Russia22,541 websites
Poland21,114 websites
France19,131 websites
Iran13,033 websites
Netherlands12,715 websites

Website Distribution by TLD

Number of websites using CVE-2017-6814
.com156,993 websites
.it45,590 websites
.ru18,721 websites
.org16,162 websites
.de15,911 websites
.pl15,162 websites
.net13,137 websites
.co.uk12,579 websites
.nl8,934 websites
.fr7,670 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2017-6814

Top websites that are affected by CVE-2017-6814. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com United States*,***
************.org United States*,***
******.com France*,***
***********.eu Cyprus*,***
*******.org United States*,***
*********.io Netherlands*,***
***********.com United States*,***
********.com United States*,***
********.org United States*,***
********.eu Austria*,***
See full domain list

FAQ

A total of 448,247 websites have been identified as vulnerable to CVE-2017-6814, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2017-6814 vulnerability.
WordPress versions up to and including 4.7.3 are vulnerable to CVE-2017-6814.