In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.
We have discovered 964,158 live websites that are affected by CVE-2019-16781.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 964,158 live websites (12% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 470 versions ( 71% of all versions) |
| 170,730 websites | |
| 98,267 websites | |
| 86,915 websites | |
| 82,841 websites | |
| 57,572 websites | |
| 49,442 websites | |
| 39,615 websites | |
| 38,611 websites | |
| 27,294 websites | |
| 21,435 websites |
| .com | 351,572 websites |
| .it | 63,924 websites |
| .ru | 47,781 websites |
| .de | 42,563 websites |
| .org | 33,447 websites |
| .net | 29,980 websites |
| .pl | 28,735 websites |
| .co.uk | 22,967 websites |
| .jp | 20,249 websites |
| .nl | 19,522 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.br | *** | ||
| *********.com | *,*** | ||
| *****.com | *,*** | ||
| ************.org | *,*** | ||
| *****.****.br | *,*** | ||
| ****.org | *,*** | ||
| *****************.com | *,*** | ||
| ********.****.br | *,*** | ||
| *******.io | *,*** | ||
| ********.eu | *,*** |
FAQ