The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.12.7. This is due to missing or incorrect nonce validation on the eae_save_config function. This makes it possible for unauthenticated attackers to change configuration settings for the plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
We have discovered 7,506 live websites that are affected by CVE-2023-4690.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 7,506 live websites (27.33% of Addon Elements For Elementor Page Builder install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 17 versions ( 44.74% of all versions) |
![]() | 1,975 websites |
![]() | 1,012 websites |
![]() | 518 websites |
![]() | 469 websites |
![]() | 353 websites |
![]() | 221 websites |
![]() | 187 websites |
![]() | 165 websites |
![]() | 146 websites |
![]() | 129 websites |
.com | 2,740 websites |
.de | 445 websites |
.ru | 361 websites |
.pl | 275 websites |
.org | 265 websites |
.com.br | 227 websites |
.fr | 171 websites |
.co.uk | 149 websites |
.net | 126 websites |
.it | 109 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********.com | ![]() | *,*** | |
***********************.com | ![]() | *,*** | |
***********.net | ![]() | **,*** | |
******.social | ![]() | **,*** | |
*************.org | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
************.********.ru | ![]() | ***,*** | |
*****************.com | ![]() | ***,*** | |
******.com | ![]() | ***,*** | |
**************.org | ![]() | ***,*** |
FAQ