The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 12,872 live websites that are affected by CVE-2024-7064.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 12,872 live websites (62.17% of ElementsKit Pro install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 82 versions ( 82.83% of all versions) |
![]() | 4,747 websites |
![]() | 1,395 websites |
![]() | 809 websites |
![]() | 595 websites |
![]() | 566 websites |
![]() | 470 websites |
![]() | 398 websites |
![]() | 329 websites |
![]() | 244 websites |
![]() | 188 websites |
.com | 5,832 websites |
.com.br | 897 websites |
.org | 547 websites |
.ru | 380 websites |
.de | 344 websites |
.co.uk | 250 websites |
.net | 222 websites |
.com.au | 194 websites |
.pl | 181 websites |
.be | 157 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*******.org | ![]() | **,*** | |
************.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
*****.org | ![]() | **,*** | |
******.com | ![]() | **,*** | |
*********.com | ![]() | ***,*** | |
**********.com | ![]() | ***,*** | |
*********.com | ![]() | ***,*** | |
**************.ru | ![]() | ***,*** | |
*************.com | ![]() | ***,*** |
FAQ