The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.
We have discovered 121,614 live websites that are affected by CVE-2024-10050.
Product | |
Category | Widgets |
Vulnerable Domains | 121,614 live websites (47.88% of Header Footer and Blocks for Elementor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 79 versions ( 84.95% of all versions) |
![]() | 36,488 websites |
![]() | 14,664 websites |
![]() | 7,820 websites |
![]() | 5,754 websites |
![]() | 4,535 websites |
![]() | 3,689 websites |
![]() | 3,633 websites |
![]() | 3,506 websites |
![]() | 3,254 websites |
![]() | 2,408 websites |
.com | 51,193 websites |
.org | 4,912 websites |
.com.br | 4,892 websites |
.de | 4,613 websites |
.co.uk | 3,002 websites |
.pl | 2,954 websites |
.ru | 2,934 websites |
.fr | 2,710 websites |
.nl | 2,412 websites |
.net | 2,411 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.com | ![]() | *,*** | |
***********************.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
**********.com | ![]() | **,*** | |
*******.co | ![]() | **,*** | |
*******************.com | ![]() | **,*** | |
*************.org | ![]() | **,*** | |
********.org | ![]() | **,*** | |
*******.org | ![]() | **,*** |
FAQ