CVE-2024-37437

WordPress Elementor Website Builder plugin <= 3.22.1 - Arbitrary SVG File Download vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Cross-Site Scripting (XSS), Stored XSS.This issue affects Elementor Website Builder: from n/a through 3.22.1.


We have discovered 983,885 live websites that are affected by CVE-2024-37437.

Test my site




Affected Software

Product  Elementor
Category Landing Page Builders
Vulnerable Domains983,885 live websites (37.70% of Elementor install base)
Vulnerable Versions
  • from 0 through 3.22.1
Vulnerable Versions Count402 versions ( 86.27% of all versions)


Common Weakness Enumeration

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')



Details

  • Published - Jul 9, 2024
  • Updated - Aug 2, 2024

Credits

  • stealthcopter (Patchstack Alliance) (finder)

CVE-2024-37437 usage by Country

United States293,159 websites



Germany124,873 websites
France67,692 websites
GB33,319 websites
Cyprus29,776 websites
Poland29,693 websites
Russia28,992 websites
Spain27,310 websites
Brazil26,724 websites
Italy23,994 websites

CVE-2024-37437 usage by TLD

.com393,586 websites
.de52,798 websites
.com.br37,221 websites
.org36,094 websites
.pl24,200 websites
.fr24,192 websites
.ru24,073 websites
.nl23,192 websites
.it21,613 websites
.co.uk21,609 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-37437

Top websites that are affected by CVE-2024-37437. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.org United States***
****.io France***
************.com United States*,***
***********.com United States*,***
**************.com United States*,***
***.***.ca Canada*,***
***********.com United States*,***
***.cz Czech Republic*,***
*********.com United States*,***
********.com United States*,***
See full domain list

FAQ

CVE-2024-37437 is Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Elementor
A total of 983,885 websites have been identified as vulnerable to CVE-2024-37437, discovered through global website indexing conducted by WebTechSurvey.
Elementor is susceptible to CVE-2024-37437 vulnerability.
Elementor versions before, and including, 3.22.1 are vulnerable to CVE-2024-37437.