The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via several parameters in all versions up to, and including, 4.10.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses and edits an injected element, and subsequently clicks the element with the mouse scroll wheel.
We have discovered 30,387 live websites that are affected by CVE-2024-5553.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 30,387 live websites (25.82% of Premium Addons for Elementor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 380 versions ( 87.56% of all versions) |
![]() | 9,511 websites |
![]() | 3,737 websites |
![]() | 1,989 websites |
![]() | 1,180 websites |
![]() | 1,070 websites |
![]() | 1,063 websites |
![]() | 1,051 websites |
![]() | 1,016 websites |
![]() | 780 websites |
![]() | 663 websites |
.com | 12,419 websites |
.com.br | 1,552 websites |
.de | 1,355 websites |
.org | 1,106 websites |
.ru | 832 websites |
.pl | 814 websites |
.co.uk | 718 websites |
.fr | 710 websites |
.it | 585 websites |
.nl | 559 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********.com | ![]() | *,*** | |
*********.com | ![]() | **,*** | |
*******************.es | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
********.es | ![]() | **,*** | |
*******.org | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
**************.com | ![]() | **,*** | |
********.**.il | ![]() | **,*** | |
*********.**.th | ![]() | **,*** |
FAQ