CVE-2024-10050

Elementor Header & Footer Builder <= 1.6.43 - Authenticated (Contributor+) Information Disclosure via Shortcode

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.


We have discovered 121,614 live websites that are affected by CVE-2024-10050.

Test my site




Affected Software

Product  Header Footer and Blocks for Elementor
Category Widgets
Vulnerable Domains121,614 live websites (47.88% of Header Footer and Blocks for Elementor install base)
Vulnerable Versions
  • from 0 through 1.6.43
Vulnerable Versions Count79 versions ( 84.95% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Oct 24, 2024
  • Updated - Oct 24, 2024

Credits

  • Francesco Carlucci (finder)

CVE-2024-10050 usage by Country

United States36,488 websites



Germany14,664 websites
France7,820 websites
Cyprus5,754 websites
GB4,535 websites
Russia3,689 websites
Poland3,633 websites
Brazil3,506 websites
Spain3,254 websites
Netherlands2,408 websites

CVE-2024-10050 usage by TLD

.com51,193 websites
.org4,912 websites
.com.br4,892 websites
.de4,613 websites
.co.uk3,002 websites
.pl2,954 websites
.ru2,934 websites
.fr2,710 websites
.nl2,412 websites
.net2,411 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-10050

Top websites that are affected by CVE-2024-10050. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com United States*,***
***********************.com United States*,***
*******.com United States*,***
**********.com United States*,***
**********.com France**,***
*******.co Germany**,***
*******************.com Germany**,***
*************.org United States**,***
********.org GB**,***
*******.org Cyprus**,***
See full domain list

FAQ

CVE-2024-10050 is Exposure of Sensitive Information to an Unauthorized Actor in Header Footer and Blocks for Elementor
A total of 121,614 websites have been identified as vulnerable to CVE-2024-10050, discovered through global website indexing conducted by WebTechSurvey.
Header Footer and Blocks for Elementor is susceptible to CVE-2024-10050 vulnerability.
Header Footer and Blocks for Elementor versions before, and including, 1.6.43 are vulnerable to CVE-2024-10050.