CVE-2024-1536

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's event calendar widget in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 43,394 live websites that are affected by CVE-2024-1536.

Test my site




Affected Software

Product  Essential Addons for Elementor
Category Wordpress Plugins
Vulnerable Domains43,394 live websites (15.24% of Essential Addons for Elementor install base)
Vulnerable Versions
  • from 0 through 5.9.9
Vulnerable Versions Count162 versions ( 78.64% of all versions)



Details

  • Published - Mar 13, 2024
  • Updated - Aug 1, 2024

Credits

  • Craig Smith (finder)

CVE-2024-1536 usage by Country

United States13,295 websites



Germany5,458 websites
France2,957 websites
Cyprus1,762 websites
GB1,596 websites
Brazil1,554 websites
Spain1,216 websites
Poland1,204 websites
Russia967 websites
Italy887 websites

CVE-2024-1536 usage by TLD

.com17,524 websites
.com.br2,217 websites
.de1,904 websites
.org1,785 websites
.fr1,047 websites
.co.uk1,009 websites
.ru1,004 websites
.pl940 websites
.net816 websites
.it763 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1536

Top websites that are affected by CVE-2024-1536. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.cz Czech Republic*,***
*******.com United States**,***
************.com United States**,***
*****************.info Bulgaria**,***
*****.pt Portugal**,***
*********************.pt Portugal**,***
********.me United States**,***
***********.com United States**,***
****.org United States**,***
***********.com United States**,***
See full domain list

FAQ

A total of 43,394 websites have been identified as vulnerable to CVE-2024-1536, discovered through global website indexing conducted by WebTechSurvey.
Essential Addons for Elementor is susceptible to CVE-2024-1536 vulnerability.
Essential Addons for Elementor versions before, and including, 5.9.9 are vulnerable to CVE-2024-1536.