The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in Elementor Editor pages. This was partially patched in version 3.23.2.
We have discovered 1,172,298 live websites that are affected by CVE-2024-5416.
Product | |
Category | Landing Page Builders |
Vulnerable Domains | 1,172,298 live websites (44.92% of Elementor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 410 versions ( 87.98% of all versions) |
![]() | 359,890 websites |
![]() | 149,073 websites |
![]() | 78,817 websites |
![]() | 39,810 websites |
![]() | 37,157 websites |
![]() | 34,655 websites |
![]() | 31,983 websites |
![]() | 31,753 websites |
![]() | 31,410 websites |
![]() | 27,925 websites |
.com | 473,622 websites |
.de | 62,694 websites |
.com.br | 45,103 websites |
.org | 43,992 websites |
.pl | 28,264 websites |
.fr | 28,200 websites |
.nl | 27,676 websites |
.ru | 26,928 websites |
.co.uk | 25,891 websites |
.net | 25,576 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.org | ![]() | *** | |
****.io | ![]() | *** | |
**************.de | ![]() | *** | |
**********.de | ![]() | *,*** | |
************.com | ![]() | *,*** | |
***********.com | ![]() | *,*** | |
**************.com | ![]() | *,*** | |
***.***.ca | ![]() | *,*** | |
***********.com | ![]() | *,*** | |
***.cz | ![]() | *,*** |
FAQ