In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
We have discovered 424,106 live websites that are affected by CVE-2017-6816.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 424,106 live websites (5.11% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 312 versions ( 47% of all versions) |
| 66,123 websites | |
| 67,172 websites | |
| 31,020 websites | |
| 25,924 websites | |
| 23,114 websites | |
| 21,823 websites | |
| 19,049 websites | |
| 17,970 websites | |
| 14,227 websites | |
| 8,194 websites |
| .com | 144,493 websites |
| .it | 43,524 websites |
| .ru | 19,388 websites |
| .org | 14,569 websites |
| .de | 14,119 websites |
| .pl | 13,542 websites |
| .net | 13,484 websites |
| .co.uk | 12,238 websites |
| .nl | 9,151 websites |
| .fr | 6,590 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| ********.eu | *,*** | ||
| ********************.ru | *,*** | ||
| ********************.com | *,*** | ||
| ****************.com | *,*** | ||
| *******.**.ca | *,*** | ||
| **********.com | **,*** | ||
| ***************.org | **,*** | ||
| *****.com | **,*** |