CVE-2024-45454

WordPress Unlimited Elements for Elementor plugin <= 1.5.121 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.121.


We have discovered 11,708 live websites that are affected by CVE-2024-45454.

Test my site




Affected Software

Product  Unlimited Elements For Elementor
Category Wordpress Plugins
Vulnerable Domains11,708 live websites (43.81% of Unlimited Elements For Elementor install base)
Vulnerable Versions
  • from 0 through 1.5.121
Vulnerable Versions Count144 versions ( 88.34% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 6, 2024
  • Updated - Oct 7, 2024

Credits

  • Rafie Muhammad (Patchstack) (finder)

CVE-2024-45454 usage by Country

United States4,427 websites



Germany1,313 websites
Cyprus670 websites
France557 websites
GB375 websites
Russia342 websites
Brazil255 websites
Italy219 websites
Poland216 websites
Spain191 websites

CVE-2024-45454 usage by TLD

.com5,329 websites
.de465 websites
.org455 websites
.com.br407 websites
.ru295 websites
.it230 websites
.co.uk230 websites
.net217 websites
.com.au196 websites
.fr186 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-45454

Top websites that are affected by CVE-2024-45454. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.cz Czech Republic*,***
*********.me United States*,***
********.com United States**,***
****.com Germany**,***
***.de Germany**,***
******.com United States**,***
**************.de Germany**,***
************.com United States**,***
***********.com United States**,***
****.org Switzerland**,***
See full domain list

FAQ

CVE-2024-45454 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Unlimited Elements For Elementor
A total of 11,708 websites have been identified as vulnerable to CVE-2024-45454, discovered through global website indexing conducted by WebTechSurvey.
Unlimited Elements For Elementor is susceptible to CVE-2024-45454 vulnerability.
Unlimited Elements For Elementor versions before, and including, 1.5.121 are vulnerable to CVE-2024-45454.