The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting through editing context via the 'data-eael-wrapper-link' wrapper in all versions up to, and including, 5.9.7 due to insufficient input sanitization and output escaping on user supplied protocols. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 40,840 live websites that are affected by CVE-2024-0954.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 40,840 live websites (14.35% of Essential Addons for Elementor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 160 versions ( 77.67% of all versions) |
![]() | 12,526 websites |
![]() | 5,119 websites |
![]() | 2,783 websites |
![]() | 1,643 websites |
![]() | 1,495 websites |
![]() | 1,469 websites |
![]() | 1,140 websites |
![]() | 1,131 websites |
![]() | 912 websites |
![]() | 845 websites |
.com | 16,464 websites |
.com.br | 2,102 websites |
.de | 1,778 websites |
.org | 1,681 websites |
.fr | 984 websites |
.ru | 961 websites |
.co.uk | 947 websites |
.pl | 881 websites |
.net | 771 websites |
.it | 718 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***.cz | ![]() | *,*** | |
*******.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
*****.pt | ![]() | **,*** | |
*********************.pt | ![]() | **,*** | |
****.org | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
*********.com | ![]() | **,*** |
FAQ