CVE-2024-5757

Elementor Header & Footer Builder <= 1.6.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Title Widget

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 56,321 live websites that are affected by CVE-2024-5757.

Run a Free Instant Scan




Affected Software

Product  Header Footer and Blocks for Elementor
Category Wordpress Plugins
Vulnerable Domains56,321 live websites (22% of Header Footer and Blocks for Elementor install base)
Vulnerable Versions
  • from 0 through 1.6.35
Vulnerable Versions Count70 versions ( 61% of all versions)



Details

  • Published - Jun 13, 2024
  • Updated - Aug 1, 2024

Credits

  • wesley (finder)

Website Distribution by Country

Number of websites using CVE-2024-5757
United States11,146 websites



Germany5,170 websites
France3,469 websites
GB2,517 websites
Russia2,413 websites
Brazil2,254 websites
Italy2,113 websites
Spain2,014 websites
India1,999 websites
Poland1,895 websites

Website Distribution by TLD

Number of websites using CVE-2024-5757
.com21,677 websites
.de2,364 websites
.com.br2,059 websites
.org2,052 websites
.ru1,912 websites
.pl1,470 websites
.it1,463 websites
.fr1,428 websites
.co.uk1,386 websites
.nl1,251 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-5757

Top websites that are affected by CVE-2024-5757. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States*,***
*******.co Serbia**,***
*****.es Spain**,***
*******.com United States**,***
***********.org United States**,***
****.com United States**,***
********.me United States**,***
*******.com United States**,***
***.sucks United States**,***
****.***.bo United States**,***
See full domain list

FAQ

A total of 56,321 websites have been identified as vulnerable to CVE-2024-5757, based on global website indexing conducted by WebTechSurvey.
The Header Footer and Blocks for Elementor is affected by the CVE-2024-5757 vulnerability.
Header Footer and Blocks for Elementor versions up to and including 1.6.35 are vulnerable to CVE-2024-5757.