WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the WordPress post and page editor, typically consisting of Authors, Contributors, and Editors making it possible to inject arbitrary web scripts into posts and pages that execute if the the_meta(); function is called on that page.
We have discovered 595,948 live websites that are affected by CVE-2022-4973.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 595,948 live websites (6.89% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 436 versions ( 66% of all versions) |
| 127,462 websites | |
| 68,670 websites | |
| 41,260 websites | |
| 40,743 websites | |
| 34,222 websites | |
| 26,672 websites | |
| 24,081 websites | |
| 22,273 websites | |
| 18,693 websites | |
| 12,358 websites |
| .com | 215,795 websites |
| .it | 44,945 websites |
| .ru | 29,240 websites |
| .org | 24,502 websites |
| .de | 19,900 websites |
| .net | 19,054 websites |
| .pl | 17,530 websites |
| .co.uk | 15,006 websites |
| .nl | 13,977 websites |
| .jp | 9,641 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.br | *** | ||
| *****.net | *** | ||
| *********.com | *** | ||
| *********.net | *** | ||
| *****.com | *,*** | ||
| ************.com | *,*** | ||
| **********.com | *,*** | ||
| ****.com | *,*** | ||
| *******.com | *,*** | ||
| ************.org | *,*** |
FAQ