WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
We have discovered 880,573 live websites that are affected by CVE-2019-17673.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 880,573 live websites (11% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 577 versions ( 69% of all versions) |
| 157,769 websites | |
| 95,300 websites | |
| 74,657 websites | |
| 69,971 websites | |
| 51,320 websites | |
| 44,884 websites | |
| 36,936 websites | |
| 36,142 websites | |
| 25,373 websites | |
| 19,608 websites |
| .com | 318,922 websites |
| .it | 62,238 websites |
| .ru | 42,666 websites |
| .de | 38,482 websites |
| .org | 30,939 websites |
| .net | 26,973 websites |
| .pl | 26,938 websites |
| .co.uk | 21,087 websites |
| .nl | 18,184 websites |
| .fr | 17,368 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.br | *** | ||
| *********.com | *,*** | ||
| *****.com | *,*** | ||
| **********.com | *,*** | ||
| ********.com | *,*** | ||
| ************.org | *,*** | ||
| ***********.eu | *,*** | ||
| *****.****.br | *,*** | ||
| *******.org | *,*** | ||
| ********.****.br | *,*** |