CVE-2024-2974

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated attackers to extract sensitive data including private and draft posts.


We have discovered 33,921 live websites that are affected by CVE-2024-2974.

Run a Free Instant Scan




Affected Software

Product  Essential Addons for Elementor
Category Wordpress Plugins
Vulnerable Domains33,921 live websites (11% of Essential Addons for Elementor install base)
Vulnerable Versions
  • from 0 through 5.9.13
Vulnerable Versions Count79 versions ( 56% of all versions)



Details

  • Published - Apr 9, 2024
  • Updated - Aug 1, 2024

Credits

  • Ankit Patel (finder)

Website Distribution by Country

Number of websites using CVE-2024-2974
United States7,078 websites



Germany3,237 websites
France2,136 websites
Brazil1,664 websites
GB1,524 websites
Italy1,405 websites
India1,297 websites
Spain1,254 websites
Poland1,031 websites
Russia883 websites

Website Distribution by TLD

Number of websites using CVE-2024-2974
.com13,088 websites
.de1,600 websites
.com.br1,527 websites
.org1,325 websites
.it996 websites
.fr898 websites
.co.uk824 websites
.pl760 websites
.ru682 websites
.net608 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-2974

Top websites that are affected by CVE-2024-2974. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States**,***
*****************.info Bulgaria**,***
*****.pt United States**,***
*********************.pt Portugal**,***
********.me United States**,***
***********.com United States**,***
******.com United States**,***
******************.com United States**,***
**************.com United States**,***
*********.com United States**,***
See full domain list

FAQ

A total of 33,921 websites have been identified as vulnerable to CVE-2024-2974, based on global website indexing conducted by WebTechSurvey.
The Essential Addons for Elementor is affected by the CVE-2024-2974 vulnerability.
Essential Addons for Elementor versions up to and including 5.9.13 are vulnerable to CVE-2024-2974.