CVE-2021-44223

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.


We have discovered 1,256,275 live websites that are affected by CVE-2021-44223.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains1,256,275 live websites (16% of WordPress install base)
Vulnerable Versions
  • from 0 through 5.8
Vulnerable Versions Count1,168 versions ( 78% of all versions)



Details

  • Published - Nov 25, 2021
  • Updated - Aug 4, 2024

Website Distribution by Country

Number of websites using CVE-2021-44223
United States246,389 websites



Japan148,693 websites
Germany107,771 websites
Italy98,421 websites
Russia66,312 websites
France64,189 websites
GB43,534 websites
Poland39,242 websites
Netherlands34,207 websites
Spain32,265 websites

Website Distribution by TLD

Number of websites using CVE-2021-44223
.com480,737 websites
.it65,081 websites
.de60,899 websites
.ru54,600 websites
.org45,859 websites
.net40,226 websites
.jp32,818 websites
.pl29,882 websites
.nl28,230 websites
.fr25,923 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-44223

Top websites that are affected by CVE-2021-44223. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org Singapore***
****.br Brazil***
*********.net United States***
*******.com United States*,***
*********.com Italy*,***
*****.com United States*,***
************.com United States*,***
********.com United States*,***
***********.com United States*,***
****.ch United States*,***
See full domain list

FAQ

A total of 1,256,275 websites have been identified as vulnerable to CVE-2021-44223, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2021-44223 vulnerability.
WordPress versions up to and including 5.8 are vulnerable to CVE-2021-44223.