CVE-2024-8979

Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_lostpassword_user_email_controls' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including usernames and passwords of any user, including Administrators, as long as that user opens the email notification for a password change request and images are not blocked by the email client.


We have discovered 60,461 live websites that are affected by CVE-2024-8979.

Run a Free Instant Scan




Affected Software

Product  Essential Addons for Elementor
Category Wordpress Plugins
Vulnerable Domains60,461 live websites (19% of Essential Addons for Elementor install base)
Vulnerable Versions
  • from 0 through 6.0.9
Vulnerable Versions Count103 versions ( 73% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Nov 15, 2024
  • Updated - Nov 15, 2024

Credits

  • wesley (finder)

Website Distribution by Country

Number of websites using CVE-2024-8979
United States13,146 websites



Germany5,691 websites
France3,623 websites
Brazil2,977 websites
GB2,646 websites
Italy2,420 websites
Spain2,373 websites
India2,218 websites
Poland1,771 websites
Russia1,410 websites

Website Distribution by TLD

Number of websites using CVE-2024-8979
.com23,633 websites
.de2,756 websites
.com.br2,722 websites
.org2,514 websites
.it1,744 websites
.fr1,534 websites
.co.uk1,433 websites
.pl1,331 websites
.ru1,120 websites
.net1,062 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8979

Top websites that are affected by CVE-2024-8979. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com United States*,***
*******.co Serbia**,***
*******.com United States**,***
********.net United States**,***
******.com Germany**,***
*****************.info Bulgaria**,***
*****.pt United States**,***
****.com United States**,***
*********************.pt Portugal**,***
********.com China**,***
See full domain list

FAQ

CVE-2024-8979 is Exposure of Sensitive Information to an Unauthorized Actor in Essential Addons for Elementor
A total of 60,461 websites have been identified as vulnerable to CVE-2024-8979, based on global website indexing conducted by WebTechSurvey.
The Essential Addons for Elementor is affected by the CVE-2024-8979 vulnerability.
Essential Addons for Elementor versions up to and including 6.0.9 are vulnerable to CVE-2024-8979.