CVE-2024-4637

Slider Revolution <= 6.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Elementor wrapperid and zindex

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' display attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 1,349,826 live websites that are affected by CVE-2024-4637.

Test my site




Affected Software

Product  Revslider
Category UI Frameworks
Vulnerable Domains1,349,826 live websites (81.35% of Revslider install base)
Vulnerable Versions
  • from 0 through 6.7.10
Vulnerable Versions Count461 versions ( 92.38% of all versions)



Details

  • Published - Jun 4, 2024
  • Updated - Aug 1, 2024

Credits

  • Matthew Rollings (finder)

CVE-2024-4637 usage by Country

United States434,200 websites



Germany167,430 websites
France91,007 websites
GB51,834 websites
Italy49,705 websites
Spain41,407 websites
Netherlands35,214 websites
Poland33,463 websites
Turkey30,738 websites
Russia27,024 websites

CVE-2024-4637 usage by TLD

.com570,098 websites
.de72,831 websites
.org47,788 websites
.it43,711 websites
.co.uk38,026 websites
.nl33,417 websites
.com.br32,274 websites
.fr30,862 websites
.pl26,637 websites
.com.au26,234 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4637

Top websites that are affected by CVE-2024-4637. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.company Denmark*,***
*******.com Netherlands*,***
****.eu United States*,***
******.com United States*,***
***********.eu Germany*,***
************.com Singapore*,***
******************.org United States*,***
****.int Canada*,***
************.ie United States*,***
**********.org United States*,***
See full domain list

FAQ

A total of 1,349,826 websites have been identified as vulnerable to CVE-2024-4637, discovered through global website indexing conducted by WebTechSurvey.
Revslider is susceptible to CVE-2024-4637 vulnerability.
Revslider versions before, and including, 6.7.10 are vulnerable to CVE-2024-4637.