CVE-2024-3889

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Accordion widget in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes like 'accordion_title_tag'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 9,279 live websites that are affected by CVE-2024-3889.

Test my site




Affected Software

Product  Royal Elementor Addons
Category Wordpress Plugins
Vulnerable Domains9,279 live websites (17.92% of Royal Elementor Addons install base)
Vulnerable Versions
  • from 0 through 1.3.971
Vulnerable Versions Count85 versions ( 70.83% of all versions)



Details

  • Published - Apr 23, 2024
  • Updated - Aug 1, 2024

Credits

  • Ngô Thiên An (finder)

CVE-2024-3889 usage by Country

United States2,384 websites



Germany1,307 websites
France783 websites
Cyprus527 websites
Brazil494 websites
Russia360 websites
Italy278 websites
GB269 websites
Poland237 websites
Spain219 websites

CVE-2024-3889 usage by TLD

.com3,574 websites
.com.br756 websites
.de420 websites
.org348 websites
.fr319 websites
.ru311 websites
.it248 websites
.pl187 websites
.net165 websites
.co.uk133 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-3889

Top websites that are affected by CVE-2024-3889. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
*********.com United States**,***
*********.com United States**,***
******.com United States**,***
***********.net United States**,***
*****.clinic Israel**,***
************.com United States***,***
******.org GB***,***
******.me United States***,***
**********.com United States***,***
See full domain list

FAQ

A total of 9,279 websites have been identified as vulnerable to CVE-2024-3889, discovered through global website indexing conducted by WebTechSurvey.
Royal Elementor Addons is susceptible to CVE-2024-3889 vulnerability.
Royal Elementor Addons versions before, and including, 1.3.971 are vulnerable to CVE-2024-3889.