The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 4,667 live websites that are affected by CVE-2024-4490.
| Product | |
| Category | Wordpress Themes |
| Vulnerable Domains | 4,667 live websites (100% of Extra install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 1,614 websites | |
| 444 websites | |
| 438 websites | |
| 235 websites | |
| 210 websites | |
| 159 websites | |
| 156 websites | |
| 128 websites | |
| 101 websites | |
| 80 websites |
| .com | 1,993 websites |
| .org | 323 websites |
| .fr | 210 websites |
| .pl | 187 websites |
| .de | 176 websites |
| .net | 145 websites |
| .it | 118 websites |
| .nl | 116 websites |
| .co.uk | 111 websites |
| .com.br | 105 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.org | **,*** | ||
| ************.com | **,*** | ||
| ***************.net | **,*** | ||
| ****************.com | **,*** | ||
| *******.com | **,*** | ||
| ********.com | ***,*** | ||
| ***********.org | ***,*** | ||
| ********.********.com | ***,*** | ||
| *********.***.tr | ***,*** | ||
| **************.it | ***,*** |