The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Open Map Widget' marker_content parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 4,294 live websites that are affected by CVE-2024-9867.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 4,294 live websites (28% of Bdthemes Element Pack Lite install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 124 versions ( 63% of all versions) |
| 958 websites | |
| 524 websites | |
| 261 websites | |
| 188 websites | |
| 176 websites | |
| 174 websites | |
| 147 websites | |
| 121 websites | |
| 118 websites | |
| 101 websites |
| .com | 1,768 websites |
| .de | 272 websites |
| .org | 171 websites |
| .com.br | 167 websites |
| .it | 116 websites |
| .fr | 107 websites |
| .nl | 97 websites |
| .pl | 84 websites |
| .net | 76 websites |
| .co.uk | 70 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *************.com | **,*** | ||
| *************.*******.***.it | **,*** | ||
| *******.org | ***,*** | ||
| *****************.com | ***,*** | ||
| **********.no | ***,*** | ||
| *********************.com | ***,*** | ||
| **************.it | ***,*** | ||
| ***********.com | ***,*** | ||
| *********.com | ***,*** | ||
| ****.***.my | ***,*** |
FAQ