The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_ext_toc_title_tag’ parameter in versions up to, and including, 5.9.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 56,908 live websites that are affected by CVE-2024-4624.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 56,908 live websites (19.99% of Essential Addons for Elementor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 173 versions ( 83.98% of all versions) |
![]() | 17,658 websites |
![]() | 7,189 websites |
![]() | 3,807 websites |
![]() | 2,501 websites |
![]() | 2,055 websites |
![]() | 2,008 websites |
![]() | 1,610 websites |
![]() | 1,592 websites |
![]() | 1,173 websites |
![]() | 1,166 websites |
.com | 23,110 websites |
.com.br | 2,888 websites |
.de | 2,497 websites |
.org | 2,409 websites |
.co.uk | 1,341 websites |
.fr | 1,332 websites |
.pl | 1,232 websites |
.ru | 1,173 websites |
.net | 1,069 websites |
.it | 1,027 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***.cz | ![]() | *,*** | |
**********.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
********.net | ![]() | **,*** | |
****.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
*****************.info | ![]() | **,*** | |
*****.pt | ![]() | **,*** | |
*********************.pt | ![]() | **,*** | |
********.me | ![]() | **,*** |
FAQ