The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 89,812 live websites that are affected by CVE-2024-5757.
Product | |
Category | Widgets |
Vulnerable Domains | 89,812 live websites (35.36% of Header Footer and Blocks for Elementor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 71 versions ( 76.34% of all versions) |
![]() | 25,675 websites |
![]() | 10,810 websites |
![]() | 5,910 websites |
![]() | 3,922 websites |
![]() | 3,344 websites |
![]() | 3,198 websites |
![]() | 2,809 websites |
![]() | 2,680 websites |
![]() | 2,469 websites |
![]() | 1,886 websites |
.com | 37,082 websites |
.com.br | 3,646 websites |
.org | 3,535 websites |
.de | 3,451 websites |
.ru | 2,536 websites |
.pl | 2,301 websites |
.co.uk | 2,150 websites |
.fr | 2,054 websites |
.nl | 1,882 websites |
.net | 1,781 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********************.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
*******.co | ![]() | **,*** | |
***.com | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
*****.es | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
***********.org | ![]() | **,*** | |
****.com | ![]() | **,*** |
FAQ