CVE-2024-24934

WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0.


We have discovered 449,984 live websites that are affected by CVE-2024-24934.

Run a Free Instant Scan




Affected Software

Product  Elementor
Category Landing Page Builders
Vulnerable Domains449,984 live websites (17% of Elementor install base)
Vulnerable Versions
  • from 0 through 3.19
Vulnerable Versions Count220 versions ( 67% of all versions)


Common Weakness Enumeration

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')



Details

  • Published - May 17, 2024
  • Updated - Aug 1, 2024

Credits

  • Rhynorater (Justin Gardner) (finder)

Website Distribution by Country

Number of websites using CVE-2024-24934
United States88,450 websites



Germany48,852 websites
France28,701 websites
Italy22,410 websites
Russia18,167 websites
GB17,492 websites
Brazil16,260 websites
Spain15,935 websites
Poland15,498 websites
Netherlands12,361 websites

Website Distribution by TLD

Number of websites using CVE-2024-24934
.com165,243 websites
.de27,182 websites
.it15,843 websites
.com.br15,022 websites
.org14,938 websites
.ru14,386 websites
.fr11,933 websites
.pl11,753 websites
.nl11,039 websites
.co.uk9,537 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-24934

Top websites that are affected by CVE-2024-24934. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.ca Canada*,***
********.com United States*,***
******.com United States*,***
**********.com United States*,***
*********.com United States*,***
**********.org United States*,***
**********.com United States*,***
****.bg Bulgaria*,***
********.com GB*,***
***************.org United States*,***
See full domain list

FAQ

CVE-2024-24934 is Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Elementor
A total of 449,984 websites have been identified as vulnerable to CVE-2024-24934, based on global website indexing conducted by WebTechSurvey.
The Elementor is affected by the CVE-2024-24934 vulnerability.
Elementor versions up to and including 3.19 are vulnerable to CVE-2024-24934.