CVE-2024-3891

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 19,846 live websites that are affected by CVE-2024-3891.

Test my site




Affected Software

Product  Happy Elementor Addons
Category Wordpress Plugins
Vulnerable Domains19,846 live websites (30.85% of Happy Elementor Addons install base)
Vulnerable Versions
  • from 0 through 3.10.5
Vulnerable Versions Count103 versions ( 80.47% of all versions)



Details

  • Published - May 2, 2024
  • Updated - Aug 1, 2024

Credits

  • wesley (finder)

CVE-2024-3891 usage by Country

United States5,722 websites



Germany2,292 websites
Brazil1,618 websites
France1,303 websites
Poland865 websites
Cyprus806 websites
Russia607 websites
GB488 websites
Japan482 websites
Spain356 websites

CVE-2024-3891 usage by TLD

.com7,183 websites
.com.br2,327 websites
.de883 websites
.pl679 websites
.org671 websites
.fr485 websites
.ru457 websites
.net351 websites
.co.uk299 websites
.it290 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-3891

Top websites that are affected by CVE-2024-3891. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********************.com United States*,***
*********.com United States**,***
*******.org United States**,***
******.net United States**,***
********.**.il Israel**,***
******.org United States**,***
********.com United States**,***
**********.jp United States***,***
************.com Austria***,***
**********.net United States***,***
See full domain list

FAQ

A total of 19,846 websites have been identified as vulnerable to CVE-2024-3891, discovered through global website indexing conducted by WebTechSurvey.
Happy Elementor Addons is susceptible to CVE-2024-3891 vulnerability.
Happy Elementor Addons versions before, and including, 3.10.5 are vulnerable to CVE-2024-3891.