The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.
We have discovered 71,852 live websites that are affected by CVE-2020-10568.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 71,852 live websites (18.96% of WPML install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 147 versions ( 65.33% of all versions) |
![]() | 12,097 websites |
![]() | 9,660 websites |
![]() | 6,845 websites |
![]() | 5,382 websites |
![]() | 4,573 websites |
![]() | 2,584 websites |
![]() | 2,209 websites |
![]() | 1,659 websites |
![]() | 1,523 websites |
![]() | 1,322 websites |
.com | 29,224 websites |
.it | 3,950 websites |
.de | 2,696 websites |
.org | 2,080 websites |
.eu | 1,895 websites |
.pl | 1,770 websites |
.es | 1,572 websites |
.nl | 1,464 websites |
.net | 1,264 websites |
.fr | 1,251 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.com | ![]() | *,*** | |
*********.be | ![]() | **,*** | |
*******.co | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
*****.******.de | ![]() | **,*** | |
***********.link | ![]() | **,*** | |
********.it | ![]() | **,*** | |
***********.com | ![]() | **,*** |
FAQ