In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
We have discovered 252,236 live websites that are affected by CVE-2020-11026.
Product | |
Category | Content Management System |
Vulnerable Domains | 252,236 live websites (2.74% of WordPress install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 346 versions ( 37.16% of all versions) |
![]() | 77,124 websites |
![]() | 25,515 websites |
![]() | 19,657 websites |
![]() | 13,501 websites |
![]() | 12,866 websites |
![]() | 8,230 websites |
![]() | 7,695 websites |
![]() | 6,876 websites |
![]() | 6,395 websites |
![]() | 6,190 websites |
.com | 103,081 websites |
.ru | 13,431 websites |
.org | 11,344 websites |
.de | 9,491 websites |
.net | 9,147 websites |
.pl | 6,446 websites |
.co.uk | 5,782 websites |
.jp | 5,737 websites |
.nl | 5,406 websites |
.fr | 5,312 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
****.******.com | ![]() | *** | |
*********.net | ![]() | *** | |
****.org | ![]() | *,*** | |
****************.com | ![]() | *,*** | |
**********.com | ![]() | **,*** | |
**********.name | ![]() | **,*** | |
******.com | ![]() | **,*** | |
********.com | ![]() | **,*** | |
*********.org | **,*** | ||
*********.kz | ![]() | **,*** |
FAQ