CVE-2021-39202

WordPress 5.8 beta: Stored Cross-Site Scripting (XSS) vulnerability in widget

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to stored XSS in the custom HTML widget. This has been patched in WordPress 5.8. It was only present during the testing/beta phase of WordPress 5.8.


We have discovered 1,256,275 live websites that are affected by CVE-2021-39202.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains1,256,275 live websites (16% of WordPress install base)
Vulnerable Versions
  • from 0 through 5.8
Vulnerable Versions Count1,168 versions ( 78% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Sep 9, 2021
  • Updated - Aug 4, 2024

Website Distribution by Country

Number of websites using CVE-2021-39202
United States246,389 websites



Japan148,693 websites
Germany107,771 websites
Italy98,421 websites
Russia66,312 websites
France64,189 websites
GB43,534 websites
Poland39,242 websites
Netherlands34,207 websites
Spain32,265 websites

Website Distribution by TLD

Number of websites using CVE-2021-39202
.com480,737 websites
.it65,081 websites
.de60,899 websites
.ru54,600 websites
.org45,859 websites
.net40,226 websites
.jp32,818 websites
.pl29,882 websites
.nl28,230 websites
.fr25,923 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-39202

Top websites that are affected by CVE-2021-39202. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org Singapore***
****.br Brazil***
*********.net United States***
*******.com United States*,***
*********.com Italy*,***
*****.com United States*,***
************.com United States*,***
********.com United States*,***
***********.com United States*,***
****.ch United States*,***
See full domain list

FAQ

CVE-2021-39202 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WordPress
A total of 1,256,275 websites have been identified as vulnerable to CVE-2021-39202, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2021-39202 vulnerability.
WordPress versions up to and including 5.8 are vulnerable to CVE-2021-39202.