The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts.
We have discovered 78,614 live websites that are affected by CVE-2020-36703.
Product | |
Category | Landing Page Builders |
Vulnerable Domains | 78,614 live websites (3.01% of Elementor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 241 versions ( 51.72% of all versions) |
![]() | 22,273 websites |
![]() | 8,239 websites |
![]() | 5,241 websites |
![]() | 3,942 websites |
![]() | 2,827 websites |
![]() | 2,807 websites |
![]() | 2,372 websites |
![]() | 2,369 websites |
![]() | 1,981 websites |
![]() | 1,731 websites |
.com | 29,490 websites |
.com.br | 4,032 websites |
.de | 3,678 websites |
.ru | 3,196 websites |
.org | 2,509 websites |
.pl | 2,282 websites |
.fr | 2,019 websites |
.co.uk | 1,687 websites |
.nl | 1,566 websites |
.it | 1,456 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********.com | ![]() | *,*** | |
*********.com | ![]() | **,*** | |
*****.org | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
****.me | ![]() | **,*** | |
*****.com | ![]() | **,*** | |
**************.info | ![]() | **,*** |