The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary HTML in pages that will be shown whenever a user accesses an injected page.
We have discovered 39,203 live websites that are affected by CVE-2024-2619.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 39,203 live websites (15% of Header Footer and Blocks for Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 59 versions ( 47% of all versions) |
| 7,436 websites | |
| 3,475 websites | |
| 2,402 websites | |
| 1,797 websites | |
| 1,758 websites | |
| 1,546 websites | |
| 1,508 websites | |
| 1,507 websites | |
| 1,430 websites | |
| 1,293 websites |
| .com | 14,739 websites |
| .de | 1,682 websites |
| .ru | 1,413 websites |
| .org | 1,398 websites |
| .com.br | 1,391 websites |
| .pl | 1,169 websites |
| .it | 1,091 websites |
| .fr | 984 websites |
| .nl | 869 websites |
| .co.uk | 856 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.com | *,*** | ||
| *******.com | **,*** | ||
| ***********.org | **,*** | ||
| ********.me | **,*** | ||
| *******.com | **,*** | ||
| ****.***.bo | **,*** | ||
| **************.com | **,*** | ||
| ***********.com | **,*** | ||
| *************.info | **,*** | ||
| **********.com | **,*** |
FAQ