The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nomore_items_text’ parameter in all versions up to, and including, 6.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 100,784 live websites that are affected by CVE-2024-8961.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 100,784 live websites (35.41% of Essential Addons for Elementor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 188 versions ( 91.26% of all versions) |
![]() | 34,283 websites |
![]() | 12,216 websites |
![]() | 6,546 websites |
![]() | 4,554 websites |
![]() | 3,552 websites |
![]() | 3,348 websites |
![]() | 2,769 websites |
![]() | 2,662 websites |
![]() | 1,964 websites |
![]() | 1,802 websites |
.com | 41,277 websites |
.com.br | 4,856 websites |
.org | 4,591 websites |
.de | 4,251 websites |
.ru | 2,823 websites |
.co.uk | 2,377 websites |
.fr | 2,344 websites |
.pl | 2,089 websites |
.net | 1,915 websites |
.com.au | 1,765 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***.cz | ![]() | *,*** | |
******.com | ![]() | *,*** | |
**********.com | ![]() | **,*** | |
*******.co | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
*************.org | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
***.ai | ![]() | **,*** | |
********.net | ![]() | **,*** | |
********.com | ![]() | **,*** |
FAQ