The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 20,939 live websites that are affected by CVE-2024-4865.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 20,939 live websites (32.55% of Happy Elementor Addons install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 106 versions ( 82.81% of all versions) |
![]() | 6,071 websites |
![]() | 2,442 websites |
![]() | 1,706 websites |
![]() | 1,359 websites |
![]() | 897 websites |
![]() | 870 websites |
![]() | 625 websites |
![]() | 515 websites |
![]() | 509 websites |
![]() | 382 websites |
.com | 7,578 websites |
.com.br | 2,478 websites |
.de | 942 websites |
.org | 716 websites |
.pl | 707 websites |
.fr | 504 websites |
.ru | 472 websites |
.net | 374 websites |
.co.uk | 316 websites |
.it | 305 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********************.com | ![]() | *,*** | |
*********.com | ![]() | **,*** | |
*******.org | ![]() | **,*** | |
******.net | ![]() | **,*** | |
********.**.il | ![]() | **,*** | |
******.org | ![]() | **,*** | |
********.com | ![]() | **,*** | |
**********.jp | ![]() | ***,*** | |
************.com | ![]() | ***,*** | |
**********.net | ![]() | ***,*** |
FAQ