Happy Addons for Elementor <= 3.20.8 - Unauthenticated Information Exposure
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.20.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 3.20.8
- Fixed in:
- 3.21.0
- Disclosed:
- May 7, 2026
CVE-2026-25468 on NVD →
Happy Addons for Elementor - Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter vulnerability
medium
Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter vulnerability
- CVSS:
- 5.4
- Affected:
- up to 3.21.0
- Fixed in:
- 3.21.1
- Disclosed:
- Mar 10, 2026
Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate_thing` admin action handler. This is due to the `can_clone()` method only checking `current_user_can('edit_posts')` (a general capability) without perf...
- CVSS:
- 5.4
- Affected:
- up to 3.21.0
- Fixed in:
- 3.21.1
- Disclosed:
- Mar 10, 2026
CVE-2026-2917 on NVD →
Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_condition_update` AJAX action. This is due to the `validate_reqeust()` method using `current_user_can('edit_posts', $template_id)` instead of `current_user_can('...
- CVSS:
- 6.4
- Affected:
- up to 3.21.0
- Fixed in:
- 3.21.1
- Disclosed:
- Mar 10, 2026
CVE-2026-2918 on NVD →
Happy Addons for Elementor <= 3.20.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_elementor_data' Meta Field
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_data' meta field in all versions up to, and including, 3.20.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access...
- CVSS:
- 6.4
- Affected:
- up to 3.20.7
- Fixed in:
- 3.20.8
- Disclosed:
- Feb 2, 2026
CVE-2026-1210 on NVD →
Happy Addons for Elementor <= 3.20.4 - Authenticated (Contributor+) SQL Injection
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.20.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level...
- CVSS:
- 6.5
- Affected:
- up to 3.20.4
- Fixed in:
- 3.20.6
- Disclosed:
- Jan 23, 2026
CVE-2025-68999 on NVD →
Happy Addons for Elementor [happy-elementor-addons] <= 3.20.4 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Blind SQL Injection.This issue affects Happy Addons for Elementor: from n/a through <= 3.20.4.
- Affected:
- up to 3.20.4
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-68999 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.20.4
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom_js' parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level...
- Affected:
- up to 3.20.4
- Fixed in:
- 3.20.4
- Disclosed:
- Dec 23, 2025
CVE-2025-14635 on NVD →
Happy Addons for Elementor <= 3.20.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom_js' parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acces...
- CVSS:
- 6.4
- Affected:
- up to 3.20.3
- Fixed in:
- 3.20.4
- Disclosed:
- Dec 22, 2025
CVE-2025-14635 on NVD →
Happy Addons for Elementor [happy-elementor-addons] <= 3.20.2 (unfixed)
unknown
[en] Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy Addons for Elementor: from n/a through <= 3.20.2.
- Affected:
- up to 3.20.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-63077 on NVD →
Happy Addons for Elementor <= 3.20.3 - Missing Authorization
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.20.3. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.20.3
- Fixed in:
- 3.20.4
- Disclosed:
- Dec 4, 2025
CVE-2025-63077 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 3.12.2
- Fixed in:
- 3.12.3
- Disclosed:
- Jul 2, 2025
CVE-2024-5647 on NVD →
Happy Addons for Elementor <= 3.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.16.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- up to 3.16.2
- Fixed in:
- 3.16.3
- Disclosed:
- Mar 27, 2025
CVE-2025-30766 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.16.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor allows DOM-Based XSS. This issue affects Happy Addons for Elementor: from n/a through 3.16.2.
- Affected:
- up to 3.16.3
- Fixed in:
- 3.16.3
- Disclosed:
- Mar 27, 2025
CVE-2025-30766 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.15.2
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wit...
- Affected:
- up to 3.15.2
- Fixed in:
- 3.15.2
- Disclosed:
- Jan 8, 2025
CVE-2024-12852 on NVD →
Happy Addons for Elementor <= 3.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Con...
- CVSS:
- 6.4
- Affected:
- up to 3.15.1
- Fixed in:
- 3.15.2
- Disclosed:
- Jan 7, 2025
CVE-2024-12852 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.12.6
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.12.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- Affected:
- up to 3.12.6
- Fixed in:
- 3.12.6
- Disclosed:
- Nov 12, 2024
CVE-2024-10538 on NVD →
Happy Addons for Elementor <= 3.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.12.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 3.12.5
- Fixed in:
- 3.12.6
- Disclosed:
- Nov 11, 2024
CVE-2024-10538 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.12.4
unknown
[en] Missing Authorization vulnerability in Leevio Happy Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy Addons for Elementor: from n/a through 3.12.3.
- Affected:
- up to 3.12.4
- Fixed in:
- 3.12.4
- Disclosed:
- Nov 1, 2024
CVE-2024-48045 on NVD →
Happy Addons for Elementor <= 3.12.3 - Missing Authorization
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_reqeust() function in versions up to, and including, 3.12.3. This makes it possible for authenticated attackers, with contributor-level access and above, to view draft/priva...
- CVSS:
- 5.4
- Affected:
- up to 3.12.3
- Fixed in:
- 3.12.4
- Disclosed:
- Oct 13, 2024
CVE-2024-48045 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.12.1
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.12.0.
- Affected:
- up to 3.12.1
- Fixed in:
- 3.12.1
- Disclosed:
- Oct 6, 2024
CVE-2024-47357 on NVD →
Happy Addons for Elementor <= 3.12.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- up to 3.12.0
- Fixed in:
- 3.12.1
- Disclosed:
- Sep 30, 2024
CVE-2024-47357 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.12.3
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including private,...
- Affected:
- up to 3.12.3
- Fixed in:
- 3.12.3
- Disclosed:
- Sep 24, 2024
CVE-2024-8801 on NVD →
Happy Addons for Elementor <= 3.12.2 - Authenticated (Contributor+) Sensitive Information Exposure
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including private, draf...
- CVSS:
- 4.3
- Affected:
- up to 3.12.2
- Fixed in:
- 3.12.3
- Disclosed:
- Sep 23, 2024
CVE-2024-8801 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.11.3
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- Affected:
- up to 3.11.3
- Fixed in:
- 3.11.3
- Disclosed:
- Jul 27, 2024
CVE-2024-6627 on NVD →
Happy Addons for Elementor <= 3.11.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via PDF View Widget
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 3.11.2
- Fixed in:
- 3.11.3
- Disclosed:
- Jul 26, 2024
CVE-2024-6627 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.11.2
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in all versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...
- Affected:
- up to 3.11.2
- Fixed in:
- 3.11.2
- Disclosed:
- Jun 29, 2024
CVE-2024-5790 on NVD →
Happy Addons for Elementor <= 3.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gradient Heading Widget
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in all versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...
- CVSS:
- 6.4
- Affected:
- up to 3.11.1
- Fixed in:
- 3.11.2
- Disclosed:
- Jun 28, 2024
CVE-2024-5790 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.11.0
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po...
- Affected:
- up to 3.11.0
- Fixed in:
- 3.11.0
- Disclosed:
- May 31, 2024
CVE-2024-5347 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.11.0
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-lev...
- Affected:
- up to 3.11.0
- Fixed in:
- 3.11.0
- Disclosed:
- May 31, 2024
CVE-2024-5041 on NVD →
Happy Addons for Elementor <= 3.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation Widget
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl...
- CVSS:
- 6.4
- Affected:
- up to 3.10.9
- Fixed in:
- 3.11.0
- Disclosed:
- May 30, 2024
CVE-2024-5347 on NVD →
Happy Addons for Elementor <= 3.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level ac...
- CVSS:
- 6.4
- Affected:
- up to 3.10.9
- Fixed in:
- 3.11.0
- Disclosed:
- May 30, 2024
CVE-2024-5041 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.9
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abo...
- Affected:
- up to 3.10.9
- Fixed in:
- 3.10.9
- Disclosed:
- May 18, 2024
CVE-2024-4865 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.9
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abo...
- Affected:
- up to 3.10.9
- Fixed in:
- 3.10.9
- Disclosed:
- May 18, 2024
CVE-2024-5088 on NVD →
Happy Addons for Elementor <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via _id Parameter
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, t...
- CVSS:
- 6.4
- Affected:
- up to 3.10.8
- Fixed in:
- 3.10.9
- Disclosed:
- May 17, 2024
CVE-2024-4865 on NVD →
Happy Addons for Elementor <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, t...
- CVSS:
- 6.4
- Affected:
- up to 3.10.8
- Fixed in:
- 3.10.9
- Disclosed:
- May 17, 2024
CVE-2024-5088 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.8
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac...
- Affected:
- up to 3.10.8
- Fixed in:
- 3.10.8
- Disclosed:
- May 16, 2024
CVE-2024-4391 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.8
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied 'tooltip_position' attribute. This makes it possible for authent...
- Affected:
- up to 3.10.8
- Fixed in:
- 3.10.8
- Disclosed:
- May 16, 2024
CVE-2024-4478 on NVD →
Happy Addons for Elementor Authenticated (Contributor+) Stored-XSS <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar Widget
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 3.10.7
- Fixed in:
- 3.10.8
- Disclosed:
- May 15, 2024
CVE-2024-4391 on NVD →
Happy Addons for Elementor <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group Widget
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied 'tooltip_position' attribute. This makes it possible for authenticate...
- CVSS:
- 6.4
- Affected:
- up to 3.10.7
- Fixed in:
- 3.10.8
- Disclosed:
- May 15, 2024
CVE-2024-4478 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.2
unknown
[en] Missing Authorization vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through 3.10.1.
- Affected:
- up to 3.10.2
- Fixed in:
- 3.10.2
- Disclosed:
- May 8, 2024
CVE-2024-24833 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.5
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Stack Group, Photo Stack, & Horizontal Timeline widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This m...
- Affected:
- up to 3.10.5
- Fixed in:
- 3.10.5
- Disclosed:
- May 2, 2024
CVE-2024-3724 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.6
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with con...
- Affected:
- up to 3.10.6
- Fixed in:
- 3.10.6
- Disclosed:
- May 2, 2024
CVE-2024-3891 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.7
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with cont...
- Affected:
- up to 3.10.7
- Fixed in:
- 3.10.7
- Disclosed:
- Apr 26, 2024
CVE-2024-3890 on NVD →
Happy Addons for Elementor <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Calendly Widget
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribut...
- CVSS:
- 6.4
- Affected:
- up to 3.10.6
- Fixed in:
- 3.10.7
- Disclosed:
- Apr 25, 2024
CVE-2024-3890 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.5
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.4.
- Affected:
- up to 3.10.5
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 22, 2024
CVE-2024-32698 on NVD →
Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 19, 2024
CVE-2024-32698 on NVD →
Happy Addons for Elementor <= 3.10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group, Photo Stack, & Horizontal Timeline
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Stack Group, Photo Stack, & Horizontal Timeline widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...
- CVSS:
- 6.4
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 19, 2024
CVE-2024-3724 on NVD →
Happy Addons for Elementor <= 3.10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...
- CVSS:
- 6.4
- Affected:
- up to 3.10.5
- Fixed in:
- 3.10.6
- Disclosed:
- Apr 19, 2024
CVE-2024-3891 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.5
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- Affected:
- up to 3.10.5
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 9, 2024
CVE-2024-2787 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.5
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization on the duplicate_thing() function in all versions up to, and including, 3.10.4. This makes it possible for attackers, with contributor-level access and above, to clone arbitrary posts...
- Affected:
- up to 3.10.5
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 9, 2024
CVE-2024-1387 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.5
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...
- Affected:
- up to 3.10.5
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 9, 2024
CVE-2024-2789 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.4
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on the title_tag attribute. This makes it possible for authenticated attackers, with contribut...
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.4
- Disclosed:
- Apr 9, 2024
CVE-2024-2786 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.5
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- Affected:
- up to 3.10.5
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 9, 2024
CVE-2024-2788 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.4
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.4
- Disclosed:
- Apr 9, 2024
CVE-2024-1498 on NVD →
Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title HTML Tag
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...
- CVSS:
- 6.4
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 4, 2024
CVE-2024-2788 on NVD →
Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title HTML Tag
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...
- CVSS:
- 6.4
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 4, 2024
CVE-2024-2787 on NVD →
Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Calendy
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with c...
- CVSS:
- 6.4
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 4, 2024
CVE-2024-2789 on NVD →
Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Stack Widget
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers wit...
- CVSS:
- 6.4
- Affected:
- up to 3.10.3
- Fixed in:
- 3.10.4
- Disclosed:
- Apr 4, 2024
CVE-2024-1498 on NVD →
Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via title_tag
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on the title_tag attribute. This makes it possible for authenticated attackers, with contributor-le...
- CVSS:
- 5.4
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 4, 2024
CVE-2024-2786 on NVD →
Happy Addons for Elementor <= 3.10.4 - Incorrect Authorization to Information Exposure
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization on the duplicate_thing() function in all versions up to, and including, 3.10.4. This makes it possible for attackers, with contributor-level access and above, to clone arbitrary posts (incl...
- CVSS:
- 4.3
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.5
- Disclosed:
- Apr 4, 2024
CVE-2024-1387 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.2
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.1.
- Affected:
- up to 3.10.2
- Fixed in:
- 3.10.2
- Disclosed:
- Mar 19, 2024
CVE-2024-29108 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.4
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_tag’ attribute of the Archive Title widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.4
- Disclosed:
- Mar 7, 2024
CVE-2024-1366 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.4
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- Affected:
- up to 3.10.4
- Fixed in:
- 3.10.4
- Disclosed:
- Mar 7, 2024
CVE-2024-1377 on NVD →
Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Archive Title Widget
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_tag’ attribute of the Archive Title widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 3.10.3
- Fixed in:
- 3.10.4
- Disclosed:
- Mar 6, 2024
CVE-2024-1366 on NVD →
Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Author Meta Widget
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 3.10.3
- Fixed in:
- 3.10.4
- Disclosed:
- Mar 6, 2024
CVE-2024-1377 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.2
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributo...
- Affected:
- up to 3.10.2
- Fixed in:
- 3.10.2
- Disclosed:
- Feb 20, 2024
CVE-2024-0438 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.2
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contrib...
- Affected:
- up to 3.10.2
- Fixed in:
- 3.10.2
- Disclosed:
- Feb 20, 2024
CVE-2024-0838 on NVD →
Happy Addons for Elementor <= 3.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor acc...
- CVSS:
- 6.4
- Affected:
- up to 3.10.1
- Fixed in:
- 3.10.2
- Disclosed:
- Feb 13, 2024
CVE-2024-0438 on NVD →
Happy Addons for Elementor <= 3.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor...
- CVSS:
- 6.4
- Affected:
- up to 3.10.1
- Fixed in:
- 3.10.2
- Disclosed:
- Feb 13, 2024
CVE-2024-0838 on NVD →
Happy Addons for Elementor <= 3.10.1 - Missing Authorization via add_row_actions
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the add_row_actions() function in versions up to, and including, 3.10.1. This makes it possible for authenticated attackers, with contributor-level access and above, to clone arbitrary p...
- CVSS:
- 4.3
- Affected:
- up to 3.10.1
- Fixed in:
- 3.10.2
- Disclosed:
- Feb 2, 2024
CVE-2024-24833 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.0
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a...
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.0
- Disclosed:
- Jan 11, 2024
CVE-2023-6632 on NVD →
Happy Elementor Addons <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AGe Gate Widget in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on the user supplied header URL value. This makes it possible for authenticated attack...
- CVSS:
- 6.4
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.1
- Disclosed:
- Jan 9, 2024
Happy Addons for Elementor [happy-elementor-addons] < 3.10.1
unknown
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AGe Gate Widget in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on the user supplied header URL value. This makes it possible for authenticated attack...
- Affected:
- up to 3.10.1
- Fixed in:
- 3.10.1
- Disclosed:
- Jan 9, 2024
Happy Addons for Elementor <= 3.9.1.1 - Reflected Cross-Site Scripting
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attack...
- CVSS:
- 6.1
- Affected:
- up to 3.9.1.1
- Fixed in:
- 3.10.0
- Disclosed:
- Jan 5, 2024
CVE-2023-6632 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.0
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through 3.9.1.1.
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.0
- Disclosed:
- Dec 29, 2023
CVE-2023-51676 on NVD →
Happy Addons for Elementor <= 3.9.1.1 - Server Side Request Forgery
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.10.0 (exclusive). This makes it possible for authenticated attackers, with contributor access and above, to make web requests to arbitrary locations originating from the web application and can be us...
- CVSS:
- 5.4
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.0
- Disclosed:
- Dec 27, 2023
CVE-2023-51676 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.8.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in weDevs Happy Addons for Elementor plugin <= 3.8.2 versions.
- Affected:
- up to 3.8.3
- Fixed in:
- 3.8.3
- Disclosed:
- Jul 10, 2023
CVE-2023-28989 on NVD →
Happy Addons for Elementor <= 3.8.2 - Cross-Site Request Forgery via handle_optin_optout()
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.2. This is due to missing nonce validation on the handle_optin_optout() function. This makes it possible for unauthenticated attackers to modify optin and optout settings, via a forged r...
- CVSS:
- 4.3
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.3
- Disclosed:
- Mar 29, 2023
CVE-2023-28989 on NVD →
Appsero <= 1.2.1 - Missing Authorization
medium
The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...
- CVSS:
- 4.3
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.3
- Disclosed:
- Dec 16, 2022
Appsero <= 1.2.0 - Cross-Site Request Forgery
medium
The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...
- CVSS:
- 4.3
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.3
- Disclosed:
- Dec 14, 2022
CVE-2022-47150 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 2.24.0
unknown
[en] The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_...
- Affected:
- up to 2.24.0
- Fixed in:
- 2.24.0
- Disclosed:
- May 17, 2021
CVE-2021-24292 on NVD →
Happy Addons for Elementor <= 2.23.0 & Pro Version < 1.17.0 - Stored Cross-Site Scripting
medium
The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_tag”...
- CVSS:
- 6.4
- Affected:
- up to 2.24.0
- Fixed in:
- 2.24.0
- Disclosed:
- Apr 26, 2021
CVE-2021-24292 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.12.3
unknown
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...
- Affected:
- up to 3.12.3
- Fixed in:
- 3.12.3
Happy Addons for Elementor [happy-elementor-addons] < 3.8.0
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.0
CVE-2022-47150 on NVD →
Happy Addons for Elementor [happy-elementor-addons] < 3.10.1
unknown
The plugin is vulnerable to Stored Cross-Site Scripting via the plugin's AGe Gate Widget in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on the user supplied header URL value. This makes it possible for authenticated attackers with contributor-level and above...
- Affected:
- up to 3.10.1
- Fixed in:
- 3.10.1