CVE-2024-4156

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_event_text_color’ parameter in versions up to, and including, 5.9.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 54,876 live websites that are affected by CVE-2024-4156.

Test my site




Affected Software

Product  Essential Addons for Elementor
Category Wordpress Plugins
Vulnerable Domains54,876 live websites (19.28% of Essential Addons for Elementor install base)
Vulnerable Versions
  • from 0 through 5.9.17
Vulnerable Versions Count170 versions ( 82.52% of all versions)



Details

  • Published - May 2, 2024
  • Updated - Aug 1, 2024

Credits

  • wesley (finder)

CVE-2024-4156 usage by Country

United States16,883 websites



Germany6,964 websites
France3,694 websites
Cyprus2,386 websites
GB1,980 websites
Brazil1,948 websites
Spain1,553 websites
Poland1,551 websites
Russia1,144 websites
Italy1,134 websites

CVE-2024-4156 usage by TLD

.com22,172 websites
.com.br2,796 websites
.de2,417 websites
.org2,295 websites
.fr1,303 websites
.co.uk1,296 websites
.pl1,206 websites
.ru1,154 websites
.net1,035 websites
.it982 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4156

Top websites that are affected by CVE-2024-4156. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.cz Czech Republic*,***
**********.com United States**,***
*******.com United States**,***
************.com United States**,***
*****************.info Bulgaria**,***
*****.pt Portugal**,***
*********************.pt Portugal**,***
********.me United States**,***
***********.com United States**,***
****.org United States**,***
See full domain list

FAQ

A total of 54,876 websites have been identified as vulnerable to CVE-2024-4156, discovered through global website indexing conducted by WebTechSurvey.
Essential Addons for Elementor is susceptible to CVE-2024-4156 vulnerability.
Essential Addons for Elementor versions before, and including, 5.9.17 are vulnerable to CVE-2024-4156.