CVE-2024-5757

Elementor Header & Footer Builder <= 1.6.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Title Widget

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 89,812 live websites that are affected by CVE-2024-5757.

Test my site




Affected Software

Product  Header Footer and Blocks for Elementor
Category Widgets
Vulnerable Domains89,812 live websites (35.36% of Header Footer and Blocks for Elementor install base)
Vulnerable Versions
  • from 0 through 1.6.35
Vulnerable Versions Count71 versions ( 76.34% of all versions)



Details

  • Published - Jun 13, 2024
  • Updated - Aug 1, 2024

Credits

  • wesley (finder)

CVE-2024-5757 usage by Country

United States25,675 websites



Germany10,810 websites
France5,910 websites
Cyprus3,922 websites
GB3,344 websites
Russia3,198 websites
Poland2,809 websites
Brazil2,680 websites
Spain2,469 websites
Netherlands1,886 websites

CVE-2024-5757 usage by TLD

.com37,082 websites
.com.br3,646 websites
.org3,535 websites
.de3,451 websites
.ru2,536 websites
.pl2,301 websites
.co.uk2,150 websites
.fr2,054 websites
.nl1,882 websites
.net1,781 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-5757

Top websites that are affected by CVE-2024-5757. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********************.com United States*,***
*******.com United States*,***
**********.com United States*,***
*******.co Germany**,***
***.com United States**,***
*******.com United States**,***
*****.es Germany**,***
*******.com United States**,***
***********.org United States**,***
****.com United States**,***
See full domain list

FAQ

A total of 89,812 websites have been identified as vulnerable to CVE-2024-5757, discovered through global website indexing conducted by WebTechSurvey.
Header Footer and Blocks for Elementor is susceptible to CVE-2024-5757 vulnerability.
Header Footer and Blocks for Elementor versions before, and including, 1.6.35 are vulnerable to CVE-2024-5757.