The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Accordion widget in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes like 'accordion_title_tag'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 9,279 live websites that are affected by CVE-2024-3889.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 9,279 live websites (17.92% of Royal Elementor Addons install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 85 versions ( 70.83% of all versions) |
![]() | 2,384 websites |
![]() | 1,307 websites |
![]() | 783 websites |
![]() | 527 websites |
![]() | 494 websites |
![]() | 360 websites |
![]() | 278 websites |
![]() | 269 websites |
![]() | 237 websites |
![]() | 219 websites |
.com | 3,574 websites |
.com.br | 756 websites |
.de | 420 websites |
.org | 348 websites |
.fr | 319 websites |
.ru | 311 websites |
.it | 248 websites |
.pl | 187 websites |
.net | 165 websites |
.co.uk | 133 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
***********.net | ![]() | **,*** | |
*****.clinic | ![]() | **,*** | |
************.com | ![]() | ***,*** | |
******.org | ![]() | ***,*** | |
******.me | ![]() | ***,*** | |
**********.com | ![]() | ***,*** |
FAQ