CVE-2024-8979

Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_lostpassword_user_email_controls' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including usernames and passwords of any user, including Administrators, as long as that user opens the email notification for a password change request and images are not blocked by the email client.


We have discovered 47,178 live websites that are affected by CVE-2024-8979.

Run a Free Instant Scan




Affected Software

Product  Essential Addons for Elementor
Category Wordpress Plugins
Vulnerable Domains47,178 live websites (16% of Essential Addons for Elementor install base)
Vulnerable Versions
  • from 0 through 6.0.9
Vulnerable Versions Count105 versions ( 66% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Nov 15, 2024
  • Updated - Apr 8, 2026

Credits

  • wesley (finder)

Website Distribution by Country

Number of websites using CVE-2024-8979
United States9,749 websites



Germany4,348 websites
France2,796 websites
Russia2,401 websites
Brazil2,303 websites
GB1,952 websites
Italy1,913 websites
Spain1,790 websites
India1,562 websites
Poland1,465 websites

Website Distribution by TLD

Number of websites using CVE-2024-8979
.com17,577 websites
.de2,170 websites
.ru2,122 websites
.com.br2,106 websites
.org1,924 websites
.it1,389 websites
.fr1,170 websites
.pl1,092 websites
.co.uk1,053 websites
.net794 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8979

Top websites that are affected by CVE-2024-8979. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com United States*,***
*******.co Serbia**,***
*******.com United States**,***
******.com Germany**,***
*****************.info Bulgaria**,***
*****.pt United States**,***
****.com United States**,***
*********************.pt Portugal**,***
********.com China**,***
********.me United States**,***
See full domain list

FAQ

CVE-2024-8979 is Exposure of Sensitive Information to an Unauthorized Actor in Essential Addons for Elementor
A total of 47,178 websites have been identified as vulnerable to CVE-2024-8979, based on global website indexing conducted by WebTechSurvey.
The Essential Addons for Elementor is affected by the CVE-2024-8979 vulnerability.
Essential Addons for Elementor versions up to and including 6.0.9 are vulnerable to CVE-2024-8979.