The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
We have discovered 8,766 live websites that are affected by CVE-2024-10493.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 8,766 live websites (54.82% of Bdthemes Element Pack Lite install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 138 versions ( 85.19% of all versions) |
![]() | 2,972 websites |
![]() | 1,171 websites |
![]() | 528 websites |
![]() | 449 websites |
![]() | 280 websites |
![]() | 263 websites |
![]() | 220 websites |
![]() | 198 websites |
![]() | 172 websites |
![]() | 144 websites |
.com | 3,849 websites |
.de | 426 websites |
.com.br | 411 websites |
.org | 356 websites |
.fr | 195 websites |
.pl | 171 websites |
.net | 166 websites |
.nl | 158 websites |
.co.uk | 153 websites |
.it | 148 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.com | ![]() | **,*** | |
******.io | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
***********.in | ![]() | **,*** | |
******.net | ![]() | **,*** | |
*********.com | ![]() | ***,*** | |
*******.org | ![]() | ***,*** | |
*****************.com | ![]() | ***,*** | |
******************.ae | ![]() | ***,*** | |
**********.no | ![]() | ***,*** |
FAQ