The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 9,675 live websites that are affected by CVE-2024-12597.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 9,675 live websites (55.28% of Ht Mega For Elementor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 145 versions ( 94.16% of all versions) |
![]() | 2,849 websites |
![]() | 1,227 websites |
![]() | 711 websites |
![]() | 451 websites |
![]() | 418 websites |
![]() | 337 websites |
![]() | 268 websites |
![]() | 239 websites |
![]() | 199 websites |
![]() | 171 websites |
.com | 3,633 websites |
.com.br | 619 websites |
.de | 485 websites |
.org | 377 websites |
.fr | 279 websites |
.pl | 272 websites |
.nl | 213 websites |
.ru | 195 websites |
.co.uk | 169 websites |
.net | 167 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.org | ![]() | **,*** | |
*****.es | ![]() | **,*** | |
****.org | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*******.org | ![]() | **,*** | |
*******.it | ![]() | **,*** | |
**.*********.***.ph | ![]() | **,*** | |
********.com | ![]() | **,*** | |
****.***.pl | ![]() | ***,*** | |
****.**.za | ![]() | ***,*** |
FAQ