CVE-2024-1567

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload dangerous file types such as .svgz on the affected site's server which may make cross-site scripting or remote code execution possible.


We have discovered 8,337 live websites that are affected by CVE-2024-1567.

Test my site




Affected Software

Product  Royal Elementor Addons
Category Wordpress Plugins
Vulnerable Domains8,337 live websites (16.10% of Royal Elementor Addons install base)
Vulnerable Versions
  • from 0 through 1.3.94
Vulnerable Versions Count80 versions ( 66.67% of all versions)



Details

  • Published - May 2, 2024
  • Updated - Aug 1, 2024

Credits

  • wesley (finder)

CVE-2024-1567 usage by Country

United States2,135 websites



Germany1,193 websites
France709 websites
Cyprus453 websites
Brazil435 websites
Russia334 websites
Italy247 websites
GB238 websites
Poland208 websites
Spain196 websites

CVE-2024-1567 usage by TLD

.com3,195 websites
.com.br665 websites
.de386 websites
.org311 websites
.fr294 websites
.ru285 websites
.it218 websites
.pl168 websites
.net152 websites
.co.uk119 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1567

Top websites that are affected by CVE-2024-1567. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**,***
*********.com United States**,***
******.com United States**,***
***********.net United States**,***
*****.clinic Israel**,***
************.com United States***,***
******.org GB***,***
******.me United States***,***
**********.com United States***,***
******.com United States***,***
See full domain list

FAQ

A total of 8,337 websites have been identified as vulnerable to CVE-2024-1567, discovered through global website indexing conducted by WebTechSurvey.
Royal Elementor Addons is susceptible to CVE-2024-1567 vulnerability.
Royal Elementor Addons versions before, and including, 1.3.94 are vulnerable to CVE-2024-1567.