The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload dangerous file types such as .svgz on the affected site's server which may make cross-site scripting or remote code execution possible.
We have discovered 8,337 live websites that are affected by CVE-2024-1567.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 8,337 live websites (16.10% of Royal Elementor Addons install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 80 versions ( 66.67% of all versions) |
![]() | 2,135 websites |
![]() | 1,193 websites |
![]() | 709 websites |
![]() | 453 websites |
![]() | 435 websites |
![]() | 334 websites |
![]() | 247 websites |
![]() | 238 websites |
![]() | 208 websites |
![]() | 196 websites |
.com | 3,195 websites |
.com.br | 665 websites |
.de | 386 websites |
.org | 311 websites |
.fr | 294 websites |
.ru | 285 websites |
.it | 218 websites |
.pl | 168 websites |
.net | 152 websites |
.co.uk | 119 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
***********.net | ![]() | **,*** | |
*****.clinic | ![]() | **,*** | |
************.com | ![]() | ***,*** | |
******.org | ![]() | ***,*** | |
******.me | ![]() | ***,*** | |
**********.com | ![]() | ***,*** | |
******.com | ![]() | ***,*** |
FAQ