The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_manual_calendar_events' function in all versions up to, and including, 5.9.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 61,573 live websites that are affected by CVE-2024-5188.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 61,573 live websites (21.63% of Essential Addons for Elementor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 175 versions ( 84.95% of all versions) |
![]() | 19,557 websites |
![]() | 7,685 websites |
![]() | 4,094 websites |
![]() | 2,724 websites |
![]() | 2,208 websites |
![]() | 2,152 websites |
![]() | 1,728 websites |
![]() | 1,675 websites |
![]() | 1,253 websites |
![]() | 1,236 websites |
.com | 24,920 websites |
.com.br | 3,094 websites |
.de | 2,665 websites |
.org | 2,615 websites |
.ru | 1,656 websites |
.co.uk | 1,437 websites |
.fr | 1,426 websites |
.pl | 1,301 websites |
.net | 1,159 websites |
.it | 1,097 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***.cz | ![]() | *,*** | |
**********.com | ![]() | **,*** | |
*******.co | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
********.net | ![]() | **,*** | |
****.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
*******.******.************.edu | **,*** | ||
*****************.info | ![]() | **,*** | |
*****.pt | ![]() | **,*** |
FAQ