CVE-2024-37437

WordPress Elementor Website Builder plugin <= 3.22.1 - Arbitrary SVG File Download vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor.This issue affects Elementor Website Builder: from n/a through <= 3.22.1.


We have discovered 494,829 live websites that are affected by CVE-2024-37437.

Run a Free Instant Scan




Affected Software

Product  Elementor
Category Landing Page Builders
Vulnerable Domains494,829 live websites (19% of Elementor install base)
Vulnerable Versions
  • from 0 through 3.22.1
Vulnerable Versions Count238 versions ( 66% of all versions)



Details

  • Published - Jul 9, 2024
  • Updated - Apr 28, 2026

Credits

  • stealthcopter | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2024-37437
United States99,349 websites



Germany50,731 websites
France30,330 websites
Italy24,791 websites
GB19,536 websites
Russia18,986 websites
Spain18,436 websites
Brazil18,425 websites
Poland17,437 websites
Netherlands13,822 websites

Website Distribution by TLD

Number of websites using CVE-2024-37437
.com184,136 websites
.de28,126 websites
.it17,698 websites
.com.br16,903 websites
.org16,361 websites
.ru15,161 websites
.pl13,259 websites
.fr12,476 websites
.nl11,907 websites
.co.uk10,279 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-37437

Top websites that are affected by CVE-2024-37437. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
******.com United States*,***
**********.com United States*,***
**.***.br Brazil*,***
*********.com United States*,***
**********.com United States*,***
****.bg Bulgaria*,***
********.com GB*,***
***************.org United States*,***
***********.*******.org Brazil**,***
See full domain list

FAQ

A total of 494,829 websites have been identified as vulnerable to CVE-2024-37437, based on global website indexing conducted by WebTechSurvey.
The Elementor is affected by the CVE-2024-37437 vulnerability.
Elementor versions up to and including 3.22.1 are vulnerable to CVE-2024-37437.