CVE-2024-37455

WordPress Ultimate Addons for elementor plugin <= 1.36.31 - Privilege Escalation vulnerability

Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.31.


We have discovered 31,720 live websites that are affected by CVE-2024-37455.

Test my site




Affected Software

Product  Ultimate Addons for Elementor
Category Wordpress Plugins
Vulnerable Domains31,720 live websites (36.44% of Ultimate Addons for Elementor install base)
Vulnerable Versions
  • from 0 through 1.36.31
Vulnerable Versions Count118 versions ( 84.89% of all versions)


Common Weakness Enumeration

CWE-269 Improper Privilege Management



Details

  • Published - Jul 9, 2024
  • Updated - Feb 7, 2025

Credits

  • NGÔ THIÊN AN / ancorn_ from VNPT-VCI (Patchstack Alliance) (finder)
  • Phan Trong Quan - VNPT Cyber Immunity (Patchstack Alliance) (finder)

CVE-2024-37455 usage by Country

United States13,616 websites



Germany3,177 websites
France1,359 websites
GB1,261 websites
Spain857 websites
Cyprus770 websites
Poland740 websites
Australia717 websites
Netherlands660 websites
Denmark602 websites

CVE-2024-37455 usage by TLD

.com14,578 websites
.de1,433 websites
.org1,201 websites
.co.uk1,086 websites
.com.au1,074 websites
.net638 websites
.com.br633 websites
.nl627 websites
.pl587 websites
.es466 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-37455

Top websites that are affected by CVE-2024-37455. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************************.***.mx United States*,***
******.***.au United States**,***
***********.com United States**,***
***************.de Germany**,***
****.net GB**,***
************.com United States**,***
***********.com United States**,***
***********.com Czech Republic**,***
*************.org United States**,***
****.***.au Australia**,***
See full domain list

FAQ

CVE-2024-37455 is Improper Privilege Management in Ultimate Addons for Elementor
A total of 31,720 websites have been identified as vulnerable to CVE-2024-37455, discovered through global website indexing conducted by WebTechSurvey.
Ultimate Addons for Elementor is susceptible to CVE-2024-37455 vulnerability.
Ultimate Addons for Elementor versions before, and including, 1.36.31 are vulnerable to CVE-2024-37455.