CVE-2024-4452

ElementsKit Pro <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 11,435 live websites that are affected by CVE-2024-4452.

Test my site




Affected Software

Product  ElementsKit Pro
Category Wordpress Plugins
Vulnerable Domains11,435 live websites (55.23% of ElementsKit Pro install base)
Vulnerable Versions
  • from 0 through 3.6.1
Vulnerable Versions Count78 versions ( 78.79% of all versions)



Details

  • Published - May 21, 2024
  • Updated - Aug 1, 2024

Credits

  • wesley (finder)

CVE-2024-4452 usage by Country

United States4,202 websites



Germany1,255 websites
Cyprus711 websites
France525 websites
Brazil514 websites
Russia444 websites
GB357 websites
Iran297 websites
Poland219 websites
Turkey165 websites

CVE-2024-4452 usage by TLD

.com5,213 websites
.com.br814 websites
.org476 websites
.ru362 websites
.de304 websites
.co.uk219 websites
.net204 websites
.com.au181 websites
.pl161 websites
.fr133 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4452

Top websites that are affected by CVE-2024-4452. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States**,***
*********.com GB**,***
*****.org United States**,***
******.com United States**,***
*********.com United States***,***
**********.com United States***,***
*********.com United States***,***
**************.ru Russia***,***
*************.com United States***,***
**************.mc Monaco***,***
See full domain list

FAQ

A total of 11,435 websites have been identified as vulnerable to CVE-2024-4452, discovered through global website indexing conducted by WebTechSurvey.
ElementsKit Pro is susceptible to CVE-2024-4452 vulnerability.
ElementsKit Pro versions before, and including, 3.6.1 are vulnerable to CVE-2024-4452.