The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to obtain contents of posts in draft, private or pending review status that should not be visible to the general public. This applies to posts created with Elementor only.
We have discovered 35,468 live websites that are affected by CVE-2023-6582.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 35,468 live websites (18.57% of ElementsKit install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 107 versions ( 75.89% of all versions) |
![]() | 10,425 websites |
![]() | 4,287 websites |
![]() | 2,110 websites |
![]() | 1,619 websites |
![]() | 1,599 websites |
![]() | 1,305 websites |
![]() | 1,151 websites |
![]() | 1,066 websites |
![]() | 772 websites |
![]() | 720 websites |
.com | 14,722 websites |
.com.br | 2,214 websites |
.org | 1,327 websites |
.de | 1,183 websites |
.ru | 933 websites |
.pl | 859 websites |
.net | 757 websites |
.fr | 666 websites |
.co.uk | 654 websites |
.com.au | 581 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*******.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
*******.nl | ![]() | **,*** | |
**************.com | ![]() | **,*** | |
********.**.il | ![]() | **,*** | |
********.**.il | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
******.com | ![]() | **,*** |
FAQ