CVE-2024-24934

WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0.


We have discovered 758,304 live websites that are affected by CVE-2024-24934.

Test my site




Affected Software

Product  Elementor
Category Landing Page Builders
Vulnerable Domains758,304 live websites (29.06% of Elementor install base)
Vulnerable Versions
  • from 0 through 3.19
Vulnerable Versions Count382 versions ( 81.97% of all versions)


Common Weakness Enumeration

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')



Details

  • Published - May 17, 2024
  • Updated - Aug 1, 2024

Credits

  • Rhynorater (Justin Gardner) (finder)

CVE-2024-24934 usage by Country

United States211,731 websites



Germany97,136 websites
France54,126 websites
GB25,787 websites
Russia25,223 websites
Poland24,026 websites
Spain21,375 websites
Brazil21,239 websites
Cyprus20,255 websites
Italy18,908 websites

CVE-2024-24934 usage by TLD

.com294,590 websites
.de41,787 websites
.com.br28,914 websites
.org26,078 websites
.ru21,039 websites
.pl19,561 websites
.fr19,344 websites
.nl18,256 websites
.co.uk16,837 websites
.it16,647 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-24934

Top websites that are affected by CVE-2024-24934. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States*,***
**************.com United States*,***
***.***.ca Canada*,***
***********.com United States*,***
********.com United States*,***
******.com United States*,***
**********.com United States*,***
**.***.br Brazil*,***
*****.com United States*,***
*********.me United States*,***
See full domain list

FAQ

CVE-2024-24934 is Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Elementor
A total of 758,304 websites have been identified as vulnerable to CVE-2024-24934, discovered through global website indexing conducted by WebTechSurvey.
Elementor is susceptible to CVE-2024-24934 vulnerability.
Elementor versions before, and including, 3.19 are vulnerable to CVE-2024-24934.