The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_event_text_color’ parameter in versions up to, and including, 5.9.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 54,876 live websites that are affected by CVE-2024-4156.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 54,876 live websites (19.28% of Essential Addons for Elementor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 170 versions ( 82.52% of all versions) |
![]() | 16,883 websites |
![]() | 6,964 websites |
![]() | 3,694 websites |
![]() | 2,386 websites |
![]() | 1,980 websites |
![]() | 1,948 websites |
![]() | 1,553 websites |
![]() | 1,551 websites |
![]() | 1,144 websites |
![]() | 1,134 websites |
.com | 22,172 websites |
.com.br | 2,796 websites |
.de | 2,417 websites |
.org | 2,295 websites |
.fr | 1,303 websites |
.co.uk | 1,296 websites |
.pl | 1,206 websites |
.ru | 1,154 websites |
.net | 1,035 websites |
.it | 982 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***.cz | ![]() | *,*** | |
**********.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
*****************.info | ![]() | **,*** | |
*****.pt | ![]() | **,*** | |
*********************.pt | ![]() | **,*** | |
********.me | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
****.org | ![]() | **,*** |
FAQ