The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated attackers to extract sensitive data including private and draft posts.
We have discovered 33,921 live websites that are affected by CVE-2024-2974.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 33,921 live websites (11% of Essential Addons for Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 79 versions ( 56% of all versions) |
| 7,078 websites | |
| 3,237 websites | |
| 2,136 websites | |
| 1,664 websites | |
| 1,524 websites | |
| 1,405 websites | |
| 1,297 websites | |
| 1,254 websites | |
| 1,031 websites | |
| 883 websites |
| .com | 13,088 websites |
| .de | 1,600 websites |
| .com.br | 1,527 websites |
| .org | 1,325 websites |
| .it | 996 websites |
| .fr | 898 websites |
| .co.uk | 824 websites |
| .pl | 760 websites |
| .ru | 682 websites |
| .net | 608 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | **,*** | ||
| *****************.info | **,*** | ||
| *****.pt | **,*** | ||
| *********************.pt | **,*** | ||
| ********.me | **,*** | ||
| ***********.com | **,*** | ||
| ******.com | **,*** | ||
| ******************.com | **,*** | ||
| **************.com | **,*** | ||
| *********.com | **,*** |
FAQ