CVE-2024-10493

Element Pack Elementor Addons < 5.10.3 - Contributor+ Stored XSS

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.


We have discovered 8,766 live websites that are affected by CVE-2024-10493.

Test my site




Affected Software

Product  Bdthemes Element Pack Lite
Category Wordpress Plugins
Vulnerable Domains8,766 live websites (54.82% of Bdthemes Element Pack Lite install base)
Vulnerable Versions
  • from 0 before 5.10.3
Vulnerable Versions Count138 versions ( 85.19% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Nov 28, 2024
  • Updated - Nov 29, 2024

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)

CVE-2024-10493 usage by Country

United States2,972 websites



Germany1,171 websites
France528 websites
Cyprus449 websites
Brazil280 websites
GB263 websites
Poland220 websites
Spain198 websites
Italy172 websites
Netherlands144 websites

CVE-2024-10493 usage by TLD

.com3,849 websites
.de426 websites
.com.br411 websites
.org356 websites
.fr195 websites
.pl171 websites
.net166 websites
.nl158 websites
.co.uk153 websites
.it148 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-10493

Top websites that are affected by CVE-2024-10493. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
******.io United States**,***
*************.com United States**,***
***********.in United States**,***
******.net United States**,***
*********.com United States***,***
*******.org United States***,***
*****************.com United States***,***
******************.ae Canada***,***
**********.no Norway***,***
See full domain list

FAQ

CVE-2024-10493 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Bdthemes Element Pack Lite
A total of 8,766 websites have been identified as vulnerable to CVE-2024-10493, discovered through global website indexing conducted by WebTechSurvey.
Bdthemes Element Pack Lite is susceptible to CVE-2024-10493 vulnerability.
Bdthemes Element Pack Lite versions before 5.10.3 are vulnerable to CVE-2024-10493.
Version 5.10.3 of Bdthemes Element Pack Lite addresses the CVE-2024-10493 security vulnerability.