CVE-2024-4624

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.20 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_ext_toc_title_tag’ parameter in versions up to, and including, 5.9.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 56,908 live websites that are affected by CVE-2024-4624.

Test my site




Affected Software

Product  Essential Addons for Elementor
Category Wordpress Plugins
Vulnerable Domains56,908 live websites (19.99% of Essential Addons for Elementor install base)
Vulnerable Versions
  • from 0 through 5.9.20
Vulnerable Versions Count173 versions ( 83.98% of all versions)



Details

  • Published - May 14, 2024
  • Updated - Aug 1, 2024

Credits

  • wesley (finder)

CVE-2024-4624 usage by Country

United States17,658 websites



Germany7,189 websites
France3,807 websites
Cyprus2,501 websites
GB2,055 websites
Brazil2,008 websites
Spain1,610 websites
Poland1,592 websites
Italy1,173 websites
Russia1,166 websites

CVE-2024-4624 usage by TLD

.com23,110 websites
.com.br2,888 websites
.de2,497 websites
.org2,409 websites
.co.uk1,341 websites
.fr1,332 websites
.pl1,232 websites
.ru1,173 websites
.net1,069 websites
.it1,027 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4624

Top websites that are affected by CVE-2024-4624. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.cz Czech Republic*,***
**********.com United States**,***
*******.com United States**,***
********.net United States**,***
****.com United States**,***
************.com United States**,***
*****************.info Bulgaria**,***
*****.pt Portugal**,***
*********************.pt Portugal**,***
********.me United States**,***
See full domain list

FAQ

A total of 56,908 websites have been identified as vulnerable to CVE-2024-4624, discovered through global website indexing conducted by WebTechSurvey.
Essential Addons for Elementor is susceptible to CVE-2024-4624 vulnerability.
Essential Addons for Elementor versions before, and including, 5.9.20 are vulnerable to CVE-2024-4624.