CVE-2024-1238

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button ID parameter in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 44,030 live websites that are affected by CVE-2024-1238.

Test my site




Affected Software

Product  ElementsKit
Category Wordpress Plugins
Vulnerable Domains44,030 live websites (23.06% of ElementsKit install base)
Vulnerable Versions
  • from 0 through 3.0.6
Vulnerable Versions Count110 versions ( 78.01% of all versions)



Details

  • Published - Mar 30, 2024
  • Updated - Aug 1, 2024

Credits

  • wesley (finder)

CVE-2024-1238 usage by Country

United States13,031 websites



Germany5,413 websites
France2,579 websites
Cyprus2,248 websites
Brazil1,932 websites
GB1,624 websites
Russia1,334 websites
Poland1,297 websites
Spain960 websites
India943 websites

CVE-2024-1238 usage by TLD

.com18,499 websites
.com.br2,708 websites
.org1,663 websites
.de1,473 websites
.ru1,089 websites
.pl1,041 websites
.net945 websites
.co.uk824 websites
.fr801 websites
.com.au729 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1238

Top websites that are affected by CVE-2024-1238. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.org United States**,***
*******.com United States**,***
************.com United States**,***
******.***.za South Africa**,***
************.com Cyprus**,***
*******.nl Netherlands**,***
**************.com United States**,***
********.**.il Israel**,***
********.**.il Israel**,***
********.**.il Israel**,***
See full domain list

FAQ

A total of 44,030 websites have been identified as vulnerable to CVE-2024-1238, discovered through global website indexing conducted by WebTechSurvey.
ElementsKit is susceptible to CVE-2024-1238 vulnerability.
ElementsKit versions before, and including, 3.0.6 are vulnerable to CVE-2024-1238.