CVE-2024-1242




The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 4.10.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.



We have discovered 56,114 live websites that are affected by CVE-2024-1242.

Contact us to get more info




Affected Software

Product  Premium Addons for Elementor
Category Widgets
Vulnerable Versions
  • from 0 through 4.10.18
Total Vulnerable Versions375
Vulnerable Domains56,114 live websites (56.93% of Premium Addons for Elementor install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2024-1242 and the relative popularity of websites


Details

  • Published - Feb 20, 2024
  • Updated - Feb 20, 2024

Credits

  • Mdr001 (finder)




Countries

United States14,235 websites



Germany3,966 websites
France3,408 websites
GB2,781 websites
Brazil2,702 websites
India2,455 websites
Italy2,325 websites
Spain1,894 websites
Poland1,674 websites
Netherlands1,365 websites

TLDs

.com23,743 websites
.de2,586 websites
.com.br2,375 websites
.org2,349 websites
.fr1,606 websites
.co.uk1,550 websites
.it1,547 websites
.pl1,273 websites
.nl1,170 websites
.ru986 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2024-1242 through included software libraries and plugins.



References


Websites affected by CVE-2024-1242

Top websites that are affected by CVE-2024-1242. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***********.com United States*,***
***.******************.org United States*,***
*************.com United States**,***
****************.com United States**,***
*************.**.uk GB**,***
***.******.com Germany**,***
*******************.nl Netherlands**,***
****************.***.ar Argentina**,***
********.ai United States**,***
***.***********.com United States**,***
See full domain list