CVE-2024-0954

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting through editing context via the 'data-eael-wrapper-link' wrapper in all versions up to, and including, 5.9.7 due to insufficient input sanitization and output escaping on user supplied protocols. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 40,840 live websites that are affected by CVE-2024-0954.

Test my site




Affected Software

Product  Essential Addons for Elementor
Category Wordpress Plugins
Vulnerable Domains40,840 live websites (14.35% of Essential Addons for Elementor install base)
Vulnerable Versions
  • from 0 through 5.9.7
Vulnerable Versions Count160 versions ( 77.67% of all versions)



Details

  • Published - Feb 5, 2024
  • Updated - Aug 1, 2024

Credits

  • Craig Smith (finder)

CVE-2024-0954 usage by Country

United States12,526 websites



Germany5,119 websites
France2,783 websites
Cyprus1,643 websites
GB1,495 websites
Brazil1,469 websites
Spain1,140 websites
Poland1,131 websites
Russia912 websites
Italy845 websites

CVE-2024-0954 usage by TLD

.com16,464 websites
.com.br2,102 websites
.de1,778 websites
.org1,681 websites
.fr984 websites
.ru961 websites
.co.uk947 websites
.pl881 websites
.net771 websites
.it718 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-0954

Top websites that are affected by CVE-2024-0954. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.cz Czech Republic*,***
*******.com United States**,***
************.com United States**,***
*****.pt Portugal**,***
*********************.pt Portugal**,***
****.org United States**,***
***********.com United States**,***
******.com United States**,***
************.com United States**,***
*********.com United Arab Emirates**,***
See full domain list

FAQ

A total of 40,840 websites have been identified as vulnerable to CVE-2024-0954, discovered through global website indexing conducted by WebTechSurvey.
Essential Addons for Elementor is susceptible to CVE-2024-0954 vulnerability.
Essential Addons for Elementor versions before, and including, 5.9.7 are vulnerable to CVE-2024-0954.