In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin extraction fails, but the PHP file remains in a predictable wp-content/uploads location, allowing for an attacker to then execute the file. This represents a security risk in limited scenarios where an attacker (who does have the required capabilities for plugin uploads) cannot simply place arbitrary PHP code into a valid plugin ZIP file and upload that plugin, because a machine's wp-content/plugins directory permissions were set up to block all new plugins.
We have discovered 530,575 live websites that are affected by CVE-2018-14028.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 530,575 live websites (6.56% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 928 versions ( 63% of all versions) |
| 106,533 websites | |
| 53,757 websites | |
| 52,220 websites | |
| 40,449 websites | |
| 29,657 websites | |
| 25,733 websites | |
| 19,908 websites | |
| 15,102 websites | |
| 12,688 websites | |
| 11,476 websites |
| .com | 199,228 websites |
| .it | 35,928 websites |
| .ru | 24,721 websites |
| .de | 20,914 websites |
| .org | 19,856 websites |
| .net | 17,641 websites |
| .jp | 12,271 websites |
| .nl | 12,056 websites |
| .co.uk | 11,685 websites |
| .fr | 10,188 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.br | *** | ||
| *******.com | *,*** | ||
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| *****.****.br | *,*** | ||
| *******.org | *,*** | ||
| ********.****.br | *,*** | ||
| *********.io | *,*** | ||
| ***********.com | *,*** | ||
| *******.com | *,*** |