Close Menu
InfovistarInfovistar
  • AI & ML
  • Cybersecurity
  • Startup
  • Tech News
  • Insights
    • Web Development
    • AWS and Cloud
    • Blockchain and Cryptocurrency
    • Chatbots
    • Technology
    • DevOps
    • Resources
  • Courses
    • Machine Learning
      • Python Tutorial
      • TensorFlow Tutorial
      • OpenCV
    • DSA
      • Data Structures
    • Web Development
      • PHP Tutorial
      • CodeIgniter Tutorial
      • CodeIgniter 4 Tutorial
      • CodeIgniter 4 AJAX
      • JavaScript
    • Mobile Development
      • Android Tutorial
  • Tools
    • Beautifier
      • HTML Beautifier
      • JavaScript Beautifier
      • CSS Beautifier
    • Online Compilers
      • Python Compiler
      • Java Compiler
      • JavaScript Editor
      • PHP Compiler
      • C++ Compiler
      • C Compiler
    • Image Optimization
      • Image Compressor
      • JPEG to PNG
      • PNG to JPEG
      • WebP to PNG

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Ransomware 2.0: How AI Is Changing Cyber Attacks Forever

April 18, 2025

Lovable AI Faces Major Threat from VibeScamming Attacks

April 10, 2025

Top Trends to Include in Your Strategy for Digital Marketing in 2025

April 5, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram Pinterest Vimeo
InfovistarInfovistar
  • AI & ML
  • Cybersecurity
  • Startup
  • Tech News
  • Insights
    • Web Development
    • AWS and Cloud
    • Blockchain and Cryptocurrency
    • Chatbots
    • Technology
    • DevOps
    • Resources
  • Courses
    • Machine Learning
      • Python Tutorial
      • TensorFlow Tutorial
      • OpenCV
    • DSA
      • Data Structures
    • Web Development
      • PHP Tutorial
      • CodeIgniter Tutorial
      • CodeIgniter 4 Tutorial
      • CodeIgniter 4 AJAX
      • JavaScript
    • Mobile Development
      • Android Tutorial
  • Tools
    • Beautifier
      • HTML Beautifier
      • JavaScript Beautifier
      • CSS Beautifier
    • Online Compilers
      • Python Compiler
      • Java Compiler
      • JavaScript Editor
      • PHP Compiler
      • C++ Compiler
      • C Compiler
    • Image Optimization
      • Image Compressor
      • JPEG to PNG
      • PNG to JPEG
      • WebP to PNG
Subscribe
InfovistarInfovistar
Home » 2M+ WordPress Sites Hit By Essential Addons For Elementor Vulnerability
Cybersecurity

2M+ WordPress Sites Hit By Essential Addons For Elementor Vulnerability

InfovistarBy InfovistarMarch 27, 2024Updated:September 1, 2024No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
2M+ WordPress Sites Hit By Essential Addons For Elementor Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email

WordPress, the world’s most popular content management system, is once again in the news, but this time, for a less-than-desirable reason. Recently, a significant vulnerability was discovered in the Essential Addons for Elementor plugin, a popular WordPress plugin with over two million active installations. This vulnerability, known as a Stored Cross-Site Scripting (XSS) vulnerability, could allow attackers to inject malicious scripts into WordPress websites.

What are Essential Addons for Elementor?

Essential Addons for Elementor is a popular WordPress plugin that extends the functionality of the Elementor page builder. It adds more features and widgets, making it easier for users to create and customize their websites.

The Vulnerability: WordPress

Security researchers discovered a Stored Cross-Site Scripting (XSS) vulnerability in the Essential Addons for Elementor plugin. This vulnerability could allow attackers to inject malicious scripts into WordPress websites. The flaws were found in two different widgets that are part of the plugin

  • Countdown Widget
    • The “Essential Addons for Elementor” plugin for WordPress, which includes Elementor templates, widgets, kits, and WooCommerce builders, is vulnerable to Stored Cross-Site Scripting through the countdown widget’s message parameter in all versions up to and including 5.9.11.
    • This allows authenticated attackers with contributor access or higher to inject arbitrary web scripts into pages, enabling execution whenever a user accesses the injected page.
  • Woo Product Carousel Widget
    • The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting through the alignment parameter in the Woo Product Carousel widget in all versions up to, and including, 5.9.10 due to insufficient input sanitization and output escaping.

XSS vulnerabilities are among the most common and arise from a failure to sanitize fields that accept inputs like text or images properly. In this case, the vulnerabilities originated from inadequate sanitization and output escaping.

The Cause: WordPress

The XSS vulnerabilities originated from inadequate sanitization and output escaping. Plugins typically “sanitize” inputs, which means that they filter out unwanted inputs like scripts. Another flaw that creates an XSS vulnerability is the failure to “escape output,” which means removing any output that contains unwanted data to prevent it from reaching a browser. Both of these flaws were cited as factors that led to the vulnerabilities.

Also read | Top 5 AI tools to chat with large PDF files

The Impact: WordPress

The impact of this vulnerability is significant. It allows an attacker to reset passwords for arbitrary accounts on any of the one million WordPress sites running the plugin. This was because the reset_password function did not adequately validate a request with a password reset key.

The Solution

The developers of the Essential Addons for Elementor plugin have released a patch to fix this vulnerability. Additionally, we strongly recommend all plugin users update to the latest version to ensure this vulnerability does not compromise their site.

The Essential Addons for Elementor vulnerability is a serious issue that affects over two million WordPress websites. Website administrators must update their plugins to the latest version to mitigate this vulnerability.

Cybersecurity WordPress
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHow Hackers are Using Generative AI to Attack Indian Businesses
Next Article Oriole Networks Secures £10M in Seed Funding
Infovistar
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

Related Posts

Cybersecurity

Ransomware 2.0: How AI Is Changing Cyber Attacks Forever

April 18, 2025
Cybersecurity

Lovable AI Faces Major Threat from VibeScamming Attacks

April 10, 2025
Cybersecurity

Hackers Target Mac Users with Apple ID Phishing Scam

March 28, 2025
Add A Comment

Comments are closed.

Blog Categories
  • AI and ML (93)
  • Android (4)
  • AWS and Cloud (7)
  • Blockchain and Cryptocurrency (6)
  • Case Study (7)
  • Chatbots (5)
  • Cybersecurity (71)
  • DevOps (5)
  • Object-Oriented Programming (2)
  • Payment Gateway (4)
  • Resources (5)
  • Search Engine Optimization (3)
  • Startup (34)
  • Tech News (70)
  • Tech Tips (12)
  • Technology (79)
  • Trading (6)
  • Web Development (23)
Top Posts

Google is rolling out Identity Check Feature to Android 15

January 25, 20252,370 Views

How to Integrate Google Gemini to WhatsApp

February 16, 20241,639 Views

OpenAI Unveils Web-Based AI Agent Operator for Task Automation

January 24, 20251,502 Views
Stay In Touch
  • Facebook
  • YouTube
  • WhatsApp
  • Twitter
  • Instagram
  • Pinterest
  • LinkedIn
Latest Articles

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

Most Popular

Google is rolling out Identity Check Feature to Android 15

January 25, 20252,370 Views

How to Integrate Google Gemini to WhatsApp

February 16, 20241,639 Views

OpenAI Unveils Web-Based AI Agent Operator for Task Automation

January 24, 20251,502 Views
Our Picks

Ransomware 2.0: How AI Is Changing Cyber Attacks Forever

April 18, 2025

Lovable AI Faces Major Threat from VibeScamming Attacks

April 10, 2025

Top Trends to Include in Your Strategy for Digital Marketing in 2025

April 5, 2025

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Facebook X (Twitter) Instagram Pinterest
  • About Us
  • Contact Us
  • Tools
  • Terms & Conditions
  • Privacy Policy
  • AdSense Disclaimer
© 2025 Infovistar. Designed and Developed by Infovistar.

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version