The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_ext_toc_title_tag’ parameter in versions up to, and including, 5.9.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 24,937 live websites that are affected by CVE-2024-4624.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 24,937 live websites (9.43% of Essential Addons for Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 88 versions ( 52% of all versions) |
| 5,002 websites | |
| 2,372 websites | |
| 1,544 websites | |
| 1,243 websites | |
| 1,068 websites | |
| 1,065 websites | |
| 949 websites | |
| 840 websites | |
| 821 websites | |
| 717 websites |
| .com | 9,349 websites |
| .de | 1,233 websites |
| .com.br | 1,138 websites |
| .org | 1,011 websites |
| .it | 771 websites |
| .fr | 645 websites |
| .pl | 607 websites |
| .ru | 556 websites |
| .co.uk | 543 websites |
| .net | 421 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | **,*** | ||
| *****************.info | **,*** | ||
| *****.pt | **,*** | ||
| *********************.pt | **,*** | ||
| ********.me | **,*** | ||
| ***********.com | **,*** | ||
| ******.com | **,*** | ||
| ********.com | **,*** | ||
| ******************.com | **,*** | ||
| **************.com | **,*** |
FAQ