In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
We have discovered 196,873 live websites that are affected by CVE-2020-11026.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 196,873 live websites (2.43% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 238 versions ( 36% of all versions) |
| 52,610 websites | |
| 19,421 websites | |
| 13,707 websites | |
| 12,576 websites | |
| 8,973 websites | |
| 8,752 websites | |
| 6,551 websites | |
| 6,204 websites | |
| 5,249 websites | |
| 4,936 websites |
| .com | 79,037 websites |
| .ru | 10,719 websites |
| .org | 9,419 websites |
| .de | 7,440 websites |
| .net | 7,061 websites |
| .it | 6,086 websites |
| .pl | 4,645 websites |
| .jp | 4,638 websites |
| .co.uk | 4,250 websites |
| .nl | 4,089 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.net | *** | ||
| ****.org | *,*** | ||
| ******.******.one | *,*** | ||
| ********************.com | *,*** | ||
| ****************.com | *,*** | ||
| **********.com | **,*** | ||
| **********.name | **,*** | ||
| ******.com | **,*** | ||
| ********.com | **,*** | ||
| *************.de | **,*** |
FAQ