The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' display attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 1,349,826 live websites that are affected by CVE-2024-4637.
Product | ![]() |
Category | UI Frameworks |
Vulnerable Domains | 1,349,826 live websites (81.35% of Revslider install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 461 versions ( 92.38% of all versions) |
![]() | 434,200 websites |
![]() | 167,430 websites |
![]() | 91,007 websites |
![]() | 51,834 websites |
![]() | 49,705 websites |
![]() | 41,407 websites |
![]() | 35,214 websites |
![]() | 33,463 websites |
![]() | 30,738 websites |
![]() | 27,024 websites |
.com | 570,098 websites |
.de | 72,831 websites |
.org | 47,788 websites |
.it | 43,711 websites |
.co.uk | 38,026 websites |
.nl | 33,417 websites |
.com.br | 32,274 websites |
.fr | 30,862 websites |
.pl | 26,637 websites |
.com.au | 26,234 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********.company | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
****.eu | ![]() | *,*** | |
******.com | ![]() | *,*** | |
***********.eu | ![]() | *,*** | |
************.com | ![]() | *,*** | |
******************.org | ![]() | *,*** | |
****.int | ![]() | *,*** | |
************.ie | ![]() | *,*** | |
**********.org | ![]() | *,*** |