CVE-2024-24831


WordPress Premium Addons for Elementor Plugin <= 4.10.16 is vulnerable to Cross Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Addons for Elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.10.16.



We have discovered 40,607 live websites that are affected by CVE-2024-24831.

Contact us to get more info




Affected Software

Product  Premium Addons for Elementor
Category Widgets
Vulnerable Versions
  • from 0 through 4.10.16
Total Vulnerable Versions375
Vulnerable Domains40,607 live websites (41.20% of Premium Addons for Elementor install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2024-24831 and the relative popularity of websites


Details

  • Published - Feb 10, 2024
  • Updated - Feb 10, 2024

Credits

  • Abu Hurayra (Patchstack Alliance) (finder)





Countries

United States9,639 websites



Germany2,634 websites
France2,233 websites
Brazil2,139 websites
India1,949 websites
GB1,916 websites
Italy1,725 websites
Spain1,422 websites
Poland1,316 websites
Russia1,105 websites

TLDs

.com16,861 websites
.com.br1,880 websites
.de1,699 websites
.org1,658 websites
.it1,158 websites
.co.uk1,035 websites
.pl997 websites
.fr968 websites
.ru882 websites
.nl785 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2024-24831 through included software libraries and plugins.



References


Websites affected by CVE-2024-24831

Top websites that are affected by CVE-2024-24831. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***********.com United States*,***
***.******************.org United States*,***
****************.com United States**,***
*************.**.uk GB**,***
********.ai United States**,***
***.***********.com United States**,***
***.*******.com United States**,***
*******.com GB**,***
***.*********.com United States**,***
***********.com France**,***
See full domain list