CVE-2024-10050

Elementor Header & Footer Builder <= 1.6.43 - Authenticated (Contributor+) Information Disclosure via Shortcode

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.


We have discovered 57,273 live websites that are affected by CVE-2024-10050.

Run a Free Instant Scan




Affected Software

Product  Header Footer and Blocks for Elementor
Category Wordpress Plugins
Vulnerable Domains57,273 live websites (22% of Header Footer and Blocks for Elementor install base)
Vulnerable Versions
  • from 0 through 1.6.43
Vulnerable Versions Count78 versions ( 63% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Oct 24, 2024
  • Updated - Apr 8, 2026

Credits

  • Francesco Carlucci (finder)

Website Distribution by Country

Number of websites using CVE-2024-10050
United States11,418 websites



Germany5,302 websites
France3,522 websites
GB2,549 websites
Brazil2,305 websites
Russia2,285 websites
Italy2,207 websites
India2,113 websites
Spain2,043 websites
Poland2,015 websites

Website Distribution by TLD

Number of websites using CVE-2024-10050
.com22,132 websites
.de2,449 websites
.com.br2,125 websites
.org2,085 websites
.ru1,800 websites
.it1,554 websites
.pl1,549 websites
.fr1,454 websites
.co.uk1,345 websites
.nl1,204 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-10050

Top websites that are affected by CVE-2024-10050. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com United States*,***
**********.com United States*,***
*******.co Serbia**,***
*******.com United States**,***
***********.org United States**,***
****.com United States**,***
********.me United States**,***
*******.com United States**,***
***.sucks United States**,***
*********************.com United States**,***
See full domain list

FAQ

CVE-2024-10050 is Exposure of Sensitive Information to an Unauthorized Actor in Header Footer and Blocks for Elementor
A total of 57,273 websites have been identified as vulnerable to CVE-2024-10050, based on global website indexing conducted by WebTechSurvey.
The Header Footer and Blocks for Elementor is affected by the CVE-2024-10050 vulnerability.
Header Footer and Blocks for Elementor versions up to and including 1.6.43 are vulnerable to CVE-2024-10050.