The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.
We have discovered 57,273 live websites that are affected by CVE-2024-10050.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 57,273 live websites (22% of Header Footer and Blocks for Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 78 versions ( 63% of all versions) |
| 11,418 websites | |
| 5,302 websites | |
| 3,522 websites | |
| 2,549 websites | |
| 2,305 websites | |
| 2,285 websites | |
| 2,207 websites | |
| 2,113 websites | |
| 2,043 websites | |
| 2,015 websites |
| .com | 22,132 websites |
| .de | 2,449 websites |
| .com.br | 2,125 websites |
| .org | 2,085 websites |
| .ru | 1,800 websites |
| .it | 1,554 websites |
| .pl | 1,549 websites |
| .fr | 1,454 websites |
| .co.uk | 1,345 websites |
| .nl | 1,204 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.com | *,*** | ||
| **********.com | *,*** | ||
| *******.co | **,*** | ||
| *******.com | **,*** | ||
| ***********.org | **,*** | ||
| ****.com | **,*** | ||
| ********.me | **,*** | ||
| *******.com | **,*** | ||
| ***.sucks | **,*** | ||
| *********************.com | **,*** |
FAQ