The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 11,435 live websites that are affected by CVE-2024-4452.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 11,435 live websites (55.23% of ElementsKit Pro install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 78 versions ( 78.79% of all versions) |
![]() | 4,202 websites |
![]() | 1,255 websites |
![]() | 711 websites |
![]() | 525 websites |
![]() | 514 websites |
![]() | 444 websites |
![]() | 357 websites |
![]() | 297 websites |
![]() | 219 websites |
![]() | 165 websites |
.com | 5,213 websites |
.com.br | 814 websites |
.org | 476 websites |
.ru | 362 websites |
.de | 304 websites |
.co.uk | 219 websites |
.net | 204 websites |
.com.au | 181 websites |
.pl | 161 websites |
.fr | 133 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
************.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
*****.org | ![]() | **,*** | |
******.com | ![]() | **,*** | |
*********.com | ![]() | ***,*** | |
**********.com | ![]() | ***,*** | |
*********.com | ![]() | ***,*** | |
**************.ru | ![]() | ***,*** | |
*************.com | ![]() | ***,*** | |
**************.mc | ![]() | ***,*** |
FAQ