CVE-2024-4342

Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, and product mini cart widgets in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 11,085 live websites that are affected by CVE-2024-4342.

Test my site




Affected Software

Product  Royal Elementor Addons
Category Wordpress Plugins
Vulnerable Domains11,085 live websites (21.41% of Royal Elementor Addons install base)
Vulnerable Versions
  • from 0 through 1.3.975
Vulnerable Versions Count89 versions ( 74.17% of all versions)



Details

  • Published - Jun 1, 2024
  • Updated - Aug 1, 2024

Credits

  • Matthew Rollings (finder)

CVE-2024-4342 usage by Country

United States2,891 websites



Germany1,549 websites
France912 websites
Cyprus661 websites
Brazil601 websites
Russia403 websites
Italy332 websites
GB319 websites
Poland282 websites
Spain274 websites

CVE-2024-4342 usage by TLD

.com4,296 websites
.com.br927 websites
.de508 websites
.org407 websites
.fr370 websites
.ru344 websites
.it295 websites
.pl217 websites
.net205 websites
.co.uk162 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4342

Top websites that are affected by CVE-2024-4342. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
*********.com United States**,***
*********.com United States**,***
******.com United States**,***
***********.net United States**,***
*****.clinic Israel**,***
************.com United States***,***
******.org GB***,***
***********.com United States***,***
******.me United States***,***
See full domain list

FAQ

A total of 11,085 websites have been identified as vulnerable to CVE-2024-4342, discovered through global website indexing conducted by WebTechSurvey.
Royal Elementor Addons is susceptible to CVE-2024-4342 vulnerability.
Royal Elementor Addons versions before, and including, 1.3.975 are vulnerable to CVE-2024-4342.

References