CVE-2023-4690

The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.12.7. This is due to missing or incorrect nonce validation on the eae_save_config function. This makes it possible for unauthenticated attackers to change configuration settings for the plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.


We have discovered 7,506 live websites that are affected by CVE-2023-4690.

Test my site




Affected Software

Product  Addon Elements For Elementor Page Builder
Category Wordpress Plugins
Vulnerable Domains7,506 live websites (27.33% of Addon Elements For Elementor Page Builder install base)
Vulnerable Versions
  • from 0 through 1.12.7
Vulnerable Versions Count17 versions ( 44.74% of all versions)



Details

  • Published - Nov 15, 2023
  • Updated - Jan 7, 2025

Credits

  • Marco Wotschka (finder)
  • Paolo Tresso (finder)

CVE-2023-4690 usage by Country

United States1,975 websites



Germany1,012 websites
France518 websites
Russia469 websites
Poland353 websites
GB221 websites
Cyprus187 websites
Brazil165 websites
Italy146 websites
Japan129 websites

CVE-2023-4690 usage by TLD

.com2,740 websites
.de445 websites
.ru361 websites
.pl275 websites
.org265 websites
.com.br227 websites
.fr171 websites
.co.uk149 websites
.net126 websites
.it109 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-4690

Top websites that are affected by CVE-2023-4690. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States*,***
***********************.com United States*,***
***********.net United States**,***
******.social United States**,***
*************.org United States**,***
*************.com United States**,***
************.********.ru Russia***,***
*****************.com United States***,***
******.com France***,***
**************.org United States***,***
See full domain list

FAQ

A total of 7,506 websites have been identified as vulnerable to CVE-2023-4690, discovered through global website indexing conducted by WebTechSurvey.
Addon Elements For Elementor Page Builder is susceptible to CVE-2023-4690 vulnerability.
Addon Elements For Elementor Page Builder versions before, and including, 1.12.7 are vulnerable to CVE-2023-4690.