The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Gallery Widget 'image_title' parameter in all versions up to, and including, 5.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 8,667 live websites that are affected by CVE-2024-10310.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 8,667 live websites (54.20% of Bdthemes Element Pack Lite install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 137 versions ( 84.57% of all versions) |
![]() | 2,932 websites |
![]() | 1,159 websites |
![]() | 526 websites |
![]() | 441 websites |
![]() | 278 websites |
![]() | 257 websites |
![]() | 220 websites |
![]() | 196 websites |
![]() | 170 websites |
![]() | 143 websites |
.com | 3,798 websites |
.de | 423 websites |
.com.br | 409 websites |
.org | 353 websites |
.fr | 194 websites |
.pl | 171 websites |
.net | 164 websites |
.nl | 156 websites |
.co.uk | 149 websites |
.it | 146 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.com | ![]() | **,*** | |
******.io | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
***********.in | ![]() | **,*** | |
******.net | ![]() | **,*** | |
*********.com | ![]() | ***,*** | |
*******.org | ![]() | ***,*** | |
*****************.com | ![]() | ***,*** | |
******************.ae | ![]() | ***,*** | |
**********.no | ![]() | ***,*** |
FAQ