WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
We have discovered 1,197,172 live websites that are affected by CVE-2019-17673.
Product | |
Category | Content Management System |
Vulnerable Domains | 1,197,172 live websites (12.99% of WordPress install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 730 versions ( 78.41% of all versions) |
![]() | 264,798 websites |
![]() | 105,163 websites |
![]() | 102,702 websites |
![]() | 93,025 websites |
![]() | 65,824 websites |
![]() | 56,990 websites |
![]() | 46,667 websites |
![]() | 43,448 websites |
![]() | 38,629 websites |
![]() | 34,867 websites |
.com | 456,781 websites |
.it | 63,903 websites |
.de | 50,208 websites |
.ru | 50,115 websites |
.org | 43,065 websites |
.net | 38,616 websites |
.pl | 33,223 websites |
.co.uk | 30,426 websites |
.com.au | 29,623 websites |
.nl | 25,965 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
****.br | ![]() | *** | |
****.******.com | ![]() | *** | |
************.***.ar | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
*****.com | ![]() | *,*** | |
****.***********.de | ![]() | *,*** | |
*************.com | ![]() | *,*** | |
************.org | ![]() | *,*** | |
***********.**.uk | ![]() | *,*** | |
*****.****.br | ![]() | *,*** |
FAQ