In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.
We have discovered 414,769 live websites that are affected by CVE-2017-9063.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 414,769 live websites (5.11% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 314 versions ( 47% of all versions) |
| 65,035 websites | |
| 65,100 websites | |
| 31,120 websites | |
| 23,970 websites | |
| 22,790 websites | |
| 21,393 websites | |
| 19,020 websites | |
| 17,451 websites | |
| 13,211 websites | |
| 8,758 websites |
| .com | 141,549 websites |
| .it | 42,136 websites |
| .ru | 19,092 websites |
| .org | 14,138 websites |
| .de | 14,116 websites |
| .pl | 13,515 websites |
| .net | 12,804 websites |
| .co.uk | 11,753 websites |
| .nl | 8,259 websites |
| .fr | 6,533 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| ********.eu | *,*** | ||
| ********************.ru | *,*** | ||
| ********************.com | *,*** | ||
| ****************.com | *,*** | ||
| *******.**.ca | *,*** | ||
| **********.com | **,*** | ||
| ***************.org | **,*** | ||
| *****.com | **,*** |