WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to stored XSS in the custom HTML widget. This has been patched in WordPress 5.8. It was only present during the testing/beta phase of WordPress 5.8.
We have discovered 1,256,275 live websites that are affected by CVE-2021-39202.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 1,256,275 live websites (16% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 1,168 versions ( 78% of all versions) |
| 246,389 websites | |
| 148,693 websites | |
| 107,771 websites | |
| 98,421 websites | |
| 66,312 websites | |
| 64,189 websites | |
| 43,534 websites | |
| 39,242 websites | |
| 34,207 websites | |
| 32,265 websites |
| .com | 480,737 websites |
| .it | 65,081 websites |
| .de | 60,899 websites |
| .ru | 54,600 websites |
| .org | 45,859 websites |
| .net | 40,226 websites |
| .jp | 32,818 websites |
| .pl | 29,882 websites |
| .nl | 28,230 websites |
| .fr | 25,923 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ************.org | *** | ||
| ****.br | *** | ||
| *********.net | *** | ||
| *******.com | *,*** | ||
| *********.com | *,*** | ||
| *****.com | *,*** | ||
| ************.com | *,*** | ||
| ********.com | *,*** | ||
| ***********.com | *,*** | ||
| ****.ch | *,*** |
FAQ