In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.
We have discovered 457,793 live websites that are affected by CVE-2017-6815.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 457,793 live websites (100% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 74,256 websites | |
| 73,655 websites | |
| 32,253 websites | |
| 27,976 websites | |
| 24,089 websites | |
| 23,257 websites | |
| 20,697 websites | |
| 19,773 websites | |
| 16,081 websites | |
| 11,392 websites |
| .com | 156,764 websites |
| .it | 48,616 websites |
| .ru | 19,503 websites |
| .de | 15,851 websites |
| .org | 15,792 websites |
| .pl | 14,846 websites |
| .net | 14,734 websites |
| .co.uk | 13,661 websites |
| .nl | 10,934 websites |
| .com.au | 8,528 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| ********.eu | *,*** | ||
| ********************.ru | *,*** | ||
| ****************.com | *,*** | ||
| *******.**.ca | *,*** | ||
| **********.com | **,*** | ||
| ***************.org | **,*** | ||
| ********.gr | **,*** | ||
| ***********.**.za | **,*** |