CVE-2024-12597

HT Mega <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner_css

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 9,675 live websites that are affected by CVE-2024-12597.

Test my site




Affected Software

Product  Ht Mega For Elementor
Category Wordpress Plugins
Vulnerable Domains9,675 live websites (55.28% of Ht Mega For Elementor install base)
Vulnerable Versions
  • from 0 through 2.7.6
Vulnerable Versions Count145 versions ( 94.16% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Feb 4, 2025
  • Updated - Feb 4, 2025

Credits

  • Sean Murphy (finder)

CVE-2024-12597 usage by Country

United States2,849 websites



Germany1,227 websites
France711 websites
Cyprus451 websites
Brazil418 websites
Poland337 websites
GB268 websites
Russia239 websites
Netherlands199 websites
Spain171 websites

CVE-2024-12597 usage by TLD

.com3,633 websites
.com.br619 websites
.de485 websites
.org377 websites
.fr279 websites
.pl272 websites
.nl213 websites
.ru195 websites
.co.uk169 websites
.net167 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-12597

Top websites that are affected by CVE-2024-12597. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.org United States**,***
*****.es Germany**,***
****.org United States**,***
***********.com United States**,***
*******.org United States**,***
*******.it United States**,***
**.*********.***.ph Philippines**,***
********.com United States**,***
****.***.pl Poland***,***
****.**.za South Africa***,***
See full domain list

FAQ

CVE-2024-12597 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Ht Mega For Elementor
A total of 9,675 websites have been identified as vulnerable to CVE-2024-12597, discovered through global website indexing conducted by WebTechSurvey.
Ht Mega For Elementor is susceptible to CVE-2024-12597 vulnerability.
Ht Mega For Elementor versions before, and including, 2.7.6 are vulnerable to CVE-2024-12597.