CVE-2023-47504

WordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerability

Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.


We have discovered 434,453 live websites that are affected by CVE-2023-47504.

Run a Free Instant Scan




Affected Software

Product  Elementor
Category Landing Page Builders
Vulnerable Domains434,453 live websites (16% of Elementor install base)
Vulnerable Versions
  • from 0 through 3.16.4
Vulnerable Versions Count207 versions ( 67% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Apr 24, 2024
  • Updated - Aug 2, 2024

Credits

  • Rafie Muhammad (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2023-47504
United States85,930 websites



Germany45,971 websites
France27,127 websites
Italy21,279 websites
Russia17,785 websites
GB16,969 websites
Brazil15,656 websites
Spain15,461 websites
Poland14,214 websites
Netherlands11,754 websites

Website Distribution by TLD

Number of websites using CVE-2023-47504
.com161,131 websites
.de25,147 websites
.it15,048 websites
.com.br14,440 websites
.org13,989 websites
.ru13,975 websites
.fr11,218 websites
.pl10,791 websites
.nl10,471 websites
.co.uk9,686 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-47504

Top websites that are affected by CVE-2023-47504. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States*,***
********.com United States*,***
******.com United States*,***
**********.com United States*,***
**.***.br Brazil*,***
*********.com United States*,***
**********.com United States*,***
********.com GB*,***
***************.org United States*,***
***********.*******.org Brazil**,***
See full domain list

FAQ

CVE-2023-47504 is Improper Authentication in Elementor
A total of 434,453 websites have been identified as vulnerable to CVE-2023-47504, based on global website indexing conducted by WebTechSurvey.
The Elementor is affected by the CVE-2023-47504 vulnerability.
Elementor versions up to and including 3.16.4 are vulnerable to CVE-2023-47504.