CVE-2020-4047

Authenticated XSS via media attachment page in WordPress

In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).


We have discovered 219,874 live websites that are affected by CVE-2020-4047.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains219,874 live websites (2.53% of WordPress install base)
Vulnerable Versions
  • from 3.7 through 3.7.34
  • from 3.8 through 3.8.34
  • from 3.9 through 3.9.32
  • from 4 through 4.0.31
  • from 4.1 through 4.1.31
  • from 4.2 through 4.2.28
  • from 4.3 through 4.3.24
  • from 4.4 through 4.4.23
  • from 4.5 through 4.5.22
  • from 4.6 through 4.6.19
  • from 4.7 through 4.7.18
  • from 4.8 through 4.8.14
  • from 4.9 through 4.9.15
  • from 5 through 5.0.10
  • from 5.1 through 5.1.6
  • from 5.2 through 5.2.7
  • from 5.3 through 5.3.4
  • from 5.4 through 5.4.2
Vulnerable Versions Count254 versions ( 38% of all versions)


Common Weakness Enumeration

CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)



Details

  • Published - Jun 12, 2020
  • Updated - Aug 4, 2024

Website Distribution by Country

Number of websites using CVE-2020-4047
United States57,392 websites



Japan23,636 websites
Germany15,197 websites
Russia13,684 websites
Italy9,816 websites
France9,636 websites
GB7,500 websites
Poland6,954 websites
Netherlands5,835 websites
Canada5,481 websites

Website Distribution by TLD

Number of websites using CVE-2020-4047
.com88,940 websites
.ru11,662 websites
.org9,993 websites
.de8,111 websites
.net8,095 websites
.it6,669 websites
.jp5,467 websites
.pl5,216 websites
.co.uk4,826 websites
.nl4,511 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-4047

Top websites that are affected by CVE-2020-4047. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.net United States***
****.org United States*,***
******.******.one Turkey*,***
****************.com United States*,***
**********.com United States**,***
**********.name United States**,***
*********.net Singapore**,***
********.com France**,***
*************.de Sweden**,***
*************.***.au Australia**,***
See full domain list

FAQ

CVE-2020-4047 is Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in WordPress
A total of 219,874 websites have been identified as vulnerable to CVE-2020-4047, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2020-4047 vulnerability.
WordPress versions up to 5.4.2 are vulnerable to CVE-2020-4047.
CVE-2020-4047 is resolved in version 5.4.2 of WordPress.