The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.
We have discovered 156,255 live websites that are affected by CVE-2023-3124.
| Product | |
| Category | Landing Page Builders |
| Vulnerable Domains | 156,255 live websites (12% of Elementor Pro install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 158 versions ( 59% of all versions) |
| 34,631 websites | |
| 14,430 websites | |
| 8,683 websites | |
| 7,737 websites | |
| 6,833 websites | |
| 6,402 websites | |
| 6,115 websites | |
| 5,800 websites | |
| 4,614 websites | |
| 4,178 websites |
| .com | 58,677 websites |
| .com.br | 8,131 websites |
| .de | 8,023 websites |
| .ru | 5,452 websites |
| .org | 4,995 websites |
| .it | 4,345 websites |
| .co.uk | 3,473 websites |
| .pl | 3,469 websites |
| .fr | 3,129 websites |
| .nl | 3,110 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **************.de | *** | ||
| ******.com | *,*** | ||
| **********.com | *,*** | ||
| **********.com | *,*** | ||
| ***************.org | *,*** | ||
| **********************.de | **,*** | ||
| ************.com | **,*** | ||
| ****.ru | **,*** | ||
| ********************.com | **,*** | ||
| ******.com | **,*** |
FAQ