CVE-2024-5818

Royal Elementor Addons and Templates <= 1.3.980 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugin's Magazine Grid/Slider widget in all versions up to, and including, 1.3.980 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 13,256 live websites that are affected by CVE-2024-5818.

Test my site




Affected Software

Product  Royal Elementor Addons
Category Wordpress Plugins
Vulnerable Domains13,256 live websites (25.60% of Royal Elementor Addons install base)
Vulnerable Versions
  • from 0 through 1.3.980
Vulnerable Versions Count94 versions ( 78.33% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 24, 2024
  • Updated - Aug 1, 2024

Credits

  • Craig Smith (finder)

CVE-2024-5818 usage by Country

United States3,473 websites



Germany1,849 websites
France1,087 websites
Cyprus818 websites
Brazil719 websites
Russia443 websites
Italy410 websites
GB373 websites
Poland345 websites
Spain332 websites

CVE-2024-5818 usage by TLD

.com5,165 websites
.com.br1,103 websites
.de618 websites
.org493 websites
.fr438 websites
.ru376 websites
.it371 websites
.pl265 websites
.net247 websites
.co.uk199 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-5818

Top websites that are affected by CVE-2024-5818. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
*********.com United States**,***
*********.com United States**,***
******.com United States**,***
***********.net United States**,***
*****.clinic Israel**,***
************.com United States***,***
******.org GB***,***
***********.com United States***,***
******.me United States***,***
See full domain list

FAQ

CVE-2024-5818 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Royal Elementor Addons
A total of 13,256 websites have been identified as vulnerable to CVE-2024-5818, discovered through global website indexing conducted by WebTechSurvey.
Royal Elementor Addons is susceptible to CVE-2024-5818 vulnerability.
Royal Elementor Addons versions before, and including, 1.3.980 are vulnerable to CVE-2024-5818.