CVE-2024-31289

WordPress Hello Elementor theme <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Hello Elementor.This issue affects Hello Elementor: from n/a through 3.0.0.


We have discovered 108,969 live websites that are affected by CVE-2024-31289.

Run a Free Instant Scan




Affected Software

Product  Hello Elementor
Category Wordpress Themes
Vulnerable Domains108,969 live websites (17% of Hello Elementor install base)
Vulnerable Versions
  • from 0 through 3
Vulnerable Versions Count28 versions ( 61% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Apr 12, 2024
  • Updated - Aug 8, 2024

Credits

  • Dhabaleshwar Das (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2024-31289
United States28,107 websites



Germany11,410 websites
Brazil7,543 websites
France5,415 websites
Italy5,134 websites
GB4,842 websites
Israel3,482 websites
Netherlands3,302 websites
Spain3,250 websites
Poland2,536 websites

Website Distribution by TLD

Number of websites using CVE-2024-31289
.com40,880 websites
.com.br7,150 websites
.de6,829 websites
.org3,740 websites
.it3,675 websites
.co.uk3,026 websites
.nl2,991 websites
.fr2,404 websites
.net2,054 websites
.ru1,940 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-31289

Top websites that are affected by CVE-2024-31289. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.ca Canada*,***
****.com United States**,***
**********************.de Germany**,***
*********************.es Spain**,***
*****.io United States**,***
******.com United States**,***
********.org United States**,***
****.com United States**,***
*********.com United States**,***
***************.com United States**,***
See full domain list

FAQ

CVE-2024-31289 is Cross-Site Request Forgery (CSRF) in Hello Elementor
A total of 108,969 websites have been identified as vulnerable to CVE-2024-31289, based on global website indexing conducted by WebTechSurvey.
The Hello Elementor is affected by the CVE-2024-31289 vulnerability.
Hello Elementor versions up to and including 3 are vulnerable to CVE-2024-31289.