CVE-2019-16781

Stored cross-site scripting (XSS) in WordPress block editor

In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.


We have discovered 964,158 live websites that are affected by CVE-2019-16781.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains964,158 live websites (12% of WordPress install base)
Vulnerable Versions
  • from 0 through 5.3.1
Vulnerable Versions Count470 versions ( 71% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 27, 2019
  • Updated - Aug 5, 2024

Website Distribution by Country

Number of websites using CVE-2019-16781
United States170,730 websites



Italy98,267 websites
Japan86,915 websites
Germany82,841 websites
Russia57,572 websites
France49,442 websites
GB39,615 websites
Poland38,611 websites
Netherlands27,294 websites
Spain21,435 websites

Website Distribution by TLD

Number of websites using CVE-2019-16781
.com351,572 websites
.it63,924 websites
.ru47,781 websites
.de42,563 websites
.org33,447 websites
.net29,980 websites
.pl28,735 websites
.co.uk22,967 websites
.jp20,249 websites
.nl19,522 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2019-16781

Top websites that are affected by CVE-2019-16781. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.br Brazil***
*********.com Italy*,***
*****.com United States*,***
************.org United States*,***
*****.****.br Brazil*,***
****.org United States*,***
*****************.com United States*,***
********.****.br Brazil*,***
*******.io Russia*,***
********.eu Austria*,***
See full domain list

FAQ

CVE-2019-16781 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WordPress
A total of 964,158 websites have been identified as vulnerable to CVE-2019-16781, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2019-16781 vulnerability.
WordPress versions up to and including 5.3.1 are vulnerable to CVE-2019-16781.