The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
We have discovered 73,419 live websites that are affected by CVE-2024-10325.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 73,419 live websites (28% of Header Footer and Blocks for Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 80 versions ( 71% of all versions) |
| 15,023 websites | |
| 6,765 websites | |
| 4,447 websites | |
| 3,334 websites | |
| 2,960 websites | |
| 2,838 websites | |
| 2,761 websites | |
| 2,699 websites | |
| 2,669 websites | |
| 2,428 websites |
| .com | 28,784 websites |
| .de | 3,022 websites |
| .org | 2,757 websites |
| .com.br | 2,719 websites |
| .ru | 2,189 websites |
| .it | 1,884 websites |
| .pl | 1,868 websites |
| .co.uk | 1,824 websites |
| .fr | 1,820 websites |
| .nl | 1,534 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.com | *,*** | ||
| **********.com | *,*** | ||
| *******.co | **,*** | ||
| *****.com | **,*** | ||
| ***.com | **,*** | ||
| *****.es | **,*** | ||
| *******.com | **,*** | ||
| ***********.org | **,*** | ||
| ****.com | **,*** | ||
| ********.me | **,*** |
FAQ