The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.
We have discovered 23,846 live websites that are affected by CVE-2021-42362.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 23,846 live websites (26.49% of WordPress Popular Posts install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 78 versions ( 60.94% of all versions) |
![]() | 4,148 websites |
![]() | 13,039 websites |
![]() | 955 websites |
![]() | 758 websites |
![]() | 484 websites |
![]() | 456 websites |
![]() | 324 websites |
![]() | 230 websites |
![]() | 181 websites |
.com | 12,585 websites |
.net | 1,939 websites |
.jp | 1,891 websites |
.ru | 1,016 websites |
.org | 699 websites |
.info | 512 websites |
.co.jp | 489 websites |
.pl | 327 websites |
.de | 300 websites |
.com.br | 244 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*************.uk | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
***************.com | ![]() | **,*** | |
*******************.com | ![]() | **,*** | |
********.tokyo | ![]() | **,*** | |
*****.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
**************.com | ![]() | **,*** | |
****.com | ![]() | **,*** |
FAQ