CVE-2023-47505


WordPress Elementor Website Builder Plugin <= 3.16.4 is vulnerable to Cross Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n/a through 3.16.4.



We have discovered 947,249 live websites that are affected by CVE-2023-47505.

Contact us to get more info




Affected Software

Product  Elementor
Category Landing Page Builders
Vulnerable Versions
  • from 0 through 3.16.4
Total Vulnerable Versions353
Vulnerable Domains947,249 live websites (37.78% of Elementor install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-47505 and the relative popularity of websites


Details

  • Published - Nov 30, 2023
  • Updated - Nov 30, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States216,084 websites



Germany74,160 websites
France54,880 websites
Brazil47,627 websites
Italy43,202 websites
GB39,711 websites
Spain34,316 websites
Poland28,225 websites
India27,714 websites
Netherlands27,047 websites

TLDs

.com383,553 websites
.de47,103 websites
.com.br41,710 websites
.org36,507 websites
.it29,108 websites
.fr22,266 websites
.nl22,190 websites
.co.uk21,897 websites
.pl21,105 websites
.net20,274 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-47505 through included software libraries and plugins.



References


Websites affected by CVE-2023-47505

Top websites that are affected by CVE-2023-47505. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*******.net Bulgaria*,***
***********.com United States*,***
**************.********.com United States*,***
***.********.com United States*,***
******.com United States*,***
**********.com United States*,***
***.**.***.br Brazil*,***
***.******.com United States*,***
***.*********.com United States*,***
***.******************.org United States*,***
See full domain list