The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button ID parameter in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 44,030 live websites that are affected by CVE-2024-1238.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 44,030 live websites (23.06% of ElementsKit install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 110 versions ( 78.01% of all versions) |
![]() | 13,031 websites |
![]() | 5,413 websites |
![]() | 2,579 websites |
![]() | 2,248 websites |
![]() | 1,932 websites |
![]() | 1,624 websites |
![]() | 1,334 websites |
![]() | 1,297 websites |
![]() | 960 websites |
![]() | 943 websites |
.com | 18,499 websites |
.com.br | 2,708 websites |
.org | 1,663 websites |
.de | 1,473 websites |
.ru | 1,089 websites |
.pl | 1,041 websites |
.net | 945 websites |
.co.uk | 824 websites |
.fr | 801 websites |
.com.au | 729 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.org | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
******.***.za | ![]() | **,*** | |
************.com | ![]() | **,*** | |
*******.nl | ![]() | **,*** | |
**************.com | ![]() | **,*** | |
********.**.il | ![]() | **,*** | |
********.**.il | ![]() | **,*** | |
********.**.il | ![]() | **,*** |
FAQ