plugin

Happy Elementor Addons Vulnerabilities

86 known security issues reported for the Happy Elementor Addons WordPress plugin. Most recent disclosed May 7, 2026.

45 medium

Running Happy Elementor Addons on your site? Check whether your installed version is affected.

Scan your site free

Happy Addons for Elementor <= 3.20.8 - Unauthenticated Information Exposure

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.20.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 3.20.8
Fixed in:
3.21.0
Disclosed:
May 7, 2026

CVE-2026-25468 on NVD →

Happy Addons for Elementor - Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter vulnerability

medium

Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter vulnerability

CVSS:
5.4
Affected:
up to 3.21.0
Fixed in:
3.21.1
Disclosed:
Mar 10, 2026

Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate_thing` admin action handler. This is due to the `can_clone()` method only checking `current_user_can('edit_posts')` (a general capability) without perf...

CVSS:
5.4
Affected:
up to 3.21.0
Fixed in:
3.21.1
Disclosed:
Mar 10, 2026

CVE-2026-2917 on NVD →

Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_condition_update` AJAX action. This is due to the `validate_reqeust()` method using `current_user_can('edit_posts', $template_id)` instead of `current_user_can('...

CVSS:
6.4
Affected:
up to 3.21.0
Fixed in:
3.21.1
Disclosed:
Mar 10, 2026

CVE-2026-2918 on NVD →

Happy Addons for Elementor <= 3.20.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_elementor_data' Meta Field

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_data' meta field in all versions up to, and including, 3.20.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access...

CVSS:
6.4
Affected:
up to 3.20.7
Fixed in:
3.20.8
Disclosed:
Feb 2, 2026

CVE-2026-1210 on NVD →

Happy Addons for Elementor <= 3.20.4 - Authenticated (Contributor+) SQL Injection

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.20.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level...

CVSS:
6.5
Affected:
up to 3.20.4
Fixed in:
3.20.6
Disclosed:
Jan 23, 2026

CVE-2025-68999 on NVD →

Happy Addons for Elementor [happy-elementor-addons] <= 3.20.4 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Blind SQL Injection.This issue affects Happy Addons for Elementor: from n/a through <= 3.20.4.

Affected:
up to 3.20.4
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-68999 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.20.4

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom_js' parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level...

Affected:
up to 3.20.4
Fixed in:
3.20.4
Disclosed:
Dec 23, 2025

CVE-2025-14635 on NVD →

Happy Addons for Elementor <= 3.20.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom_js' parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acces...

CVSS:
6.4
Affected:
up to 3.20.3
Fixed in:
3.20.4
Disclosed:
Dec 22, 2025

CVE-2025-14635 on NVD →

Happy Addons for Elementor [happy-elementor-addons] <= 3.20.2 (unfixed)

unknown

[en] Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy Addons for Elementor: from n/a through <= 3.20.2.

Affected:
up to 3.20.2
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-63077 on NVD →

Happy Addons for Elementor <= 3.20.3 - Missing Authorization

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.20.3. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.20.3
Fixed in:
3.20.4
Disclosed:
Dec 4, 2025

CVE-2025-63077 on NVD →

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library

medium

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...

CVSS:
6.4
Affected:
up to 3.12.2
Fixed in:
3.12.3
Disclosed:
Jul 2, 2025

CVE-2024-5647 on NVD →

Happy Addons for Elementor <= 3.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.16.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scrip...

CVSS:
6.4
Affected:
up to 3.16.2
Fixed in:
3.16.3
Disclosed:
Mar 27, 2025

CVE-2025-30766 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.16.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor allows DOM-Based XSS. This issue affects Happy Addons for Elementor: from n/a through 3.16.2.

Affected:
up to 3.16.3
Fixed in:
3.16.3
Disclosed:
Mar 27, 2025

CVE-2025-30766 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.15.2

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wit...

Affected:
up to 3.15.2
Fixed in:
3.15.2
Disclosed:
Jan 8, 2025

CVE-2024-12852 on NVD →

Happy Addons for Elementor <= 3.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Con...

CVSS:
6.4
Affected:
up to 3.15.1
Fixed in:
3.15.2
Disclosed:
Jan 7, 2025

CVE-2024-12852 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.12.6

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.12.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

Affected:
up to 3.12.6
Fixed in:
3.12.6
Disclosed:
Nov 12, 2024

CVE-2024-10538 on NVD →

Happy Addons for Elementor <= 3.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.12.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 3.12.5
Fixed in:
3.12.6
Disclosed:
Nov 11, 2024

CVE-2024-10538 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.12.4

unknown

[en] Missing Authorization vulnerability in Leevio Happy Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy Addons for Elementor: from n/a through 3.12.3.

Affected:
up to 3.12.4
Fixed in:
3.12.4
Disclosed:
Nov 1, 2024

CVE-2024-48045 on NVD →

Happy Addons for Elementor <= 3.12.3 - Missing Authorization

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_reqeust() function in versions up to, and including, 3.12.3. This makes it possible for authenticated attackers, with contributor-level access and above, to view draft/priva...

CVSS:
5.4
Affected:
up to 3.12.3
Fixed in:
3.12.4
Disclosed:
Oct 13, 2024

CVE-2024-48045 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.12.1

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.12.0.

Affected:
up to 3.12.1
Fixed in:
3.12.1
Disclosed:
Oct 6, 2024

CVE-2024-47357 on NVD →

Happy Addons for Elementor <= 3.12.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scrip...

CVSS:
6.4
Affected:
up to 3.12.0
Fixed in:
3.12.1
Disclosed:
Sep 30, 2024

CVE-2024-47357 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.12.3

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including private,...

Affected:
up to 3.12.3
Fixed in:
3.12.3
Disclosed:
Sep 24, 2024

CVE-2024-8801 on NVD →

Happy Addons for Elementor <= 3.12.2 - Authenticated (Contributor+) Sensitive Information Exposure

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including private, draf...

CVSS:
4.3
Affected:
up to 3.12.2
Fixed in:
3.12.3
Disclosed:
Sep 23, 2024

CVE-2024-8801 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.11.3

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...

Affected:
up to 3.11.3
Fixed in:
3.11.3
Disclosed:
Jul 27, 2024

CVE-2024-6627 on NVD →

Happy Addons for Elementor <= 3.11.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via PDF View Widget

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 3.11.2
Fixed in:
3.11.3
Disclosed:
Jul 26, 2024

CVE-2024-6627 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.11.2

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in all versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...

Affected:
up to 3.11.2
Fixed in:
3.11.2
Disclosed:
Jun 29, 2024

CVE-2024-5790 on NVD →

Happy Addons for Elementor <= 3.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gradient Heading Widget

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in all versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

CVSS:
6.4
Affected:
up to 3.11.1
Fixed in:
3.11.2
Disclosed:
Jun 28, 2024

CVE-2024-5790 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.11.0

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po...

Affected:
up to 3.11.0
Fixed in:
3.11.0
Disclosed:
May 31, 2024

CVE-2024-5347 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.11.0

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-lev...

Affected:
up to 3.11.0
Fixed in:
3.11.0
Disclosed:
May 31, 2024

CVE-2024-5041 on NVD →

Happy Addons for Elementor <= 3.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation Widget

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl...

CVSS:
6.4
Affected:
up to 3.10.9
Fixed in:
3.11.0
Disclosed:
May 30, 2024

CVE-2024-5347 on NVD →

Happy Addons for Elementor <= 3.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level ac...

CVSS:
6.4
Affected:
up to 3.10.9
Fixed in:
3.11.0
Disclosed:
May 30, 2024

CVE-2024-5041 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.9

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abo...

Affected:
up to 3.10.9
Fixed in:
3.10.9
Disclosed:
May 18, 2024

CVE-2024-4865 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.9

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abo...

Affected:
up to 3.10.9
Fixed in:
3.10.9
Disclosed:
May 18, 2024

CVE-2024-5088 on NVD →

Happy Addons for Elementor <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via _id Parameter

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, t...

CVSS:
6.4
Affected:
up to 3.10.8
Fixed in:
3.10.9
Disclosed:
May 17, 2024

CVE-2024-4865 on NVD →

Happy Addons for Elementor <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, t...

CVSS:
6.4
Affected:
up to 3.10.8
Fixed in:
3.10.9
Disclosed:
May 17, 2024

CVE-2024-5088 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.8

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac...

Affected:
up to 3.10.8
Fixed in:
3.10.8
Disclosed:
May 16, 2024

CVE-2024-4391 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.8

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied 'tooltip_position' attribute. This makes it possible for authent...

Affected:
up to 3.10.8
Fixed in:
3.10.8
Disclosed:
May 16, 2024

CVE-2024-4478 on NVD →

Happy Addons for Elementor Authenticated (Contributor+) Stored-XSS <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar Widget

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...

CVSS:
6.4
Affected:
up to 3.10.7
Fixed in:
3.10.8
Disclosed:
May 15, 2024

CVE-2024-4391 on NVD →

Happy Addons for Elementor <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group Widget

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied 'tooltip_position' attribute. This makes it possible for authenticate...

CVSS:
6.4
Affected:
up to 3.10.7
Fixed in:
3.10.8
Disclosed:
May 15, 2024

CVE-2024-4478 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.2

unknown

[en] Missing Authorization vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through 3.10.1.

Affected:
up to 3.10.2
Fixed in:
3.10.2
Disclosed:
May 8, 2024

CVE-2024-24833 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.5

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Stack Group, Photo Stack, & Horizontal Timeline widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This m...

Affected:
up to 3.10.5
Fixed in:
3.10.5
Disclosed:
May 2, 2024

CVE-2024-3724 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.6

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with con...

Affected:
up to 3.10.6
Fixed in:
3.10.6
Disclosed:
May 2, 2024

CVE-2024-3891 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.7

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with cont...

Affected:
up to 3.10.7
Fixed in:
3.10.7
Disclosed:
Apr 26, 2024

CVE-2024-3890 on NVD →

Happy Addons for Elementor <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Calendly Widget

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribut...

CVSS:
6.4
Affected:
up to 3.10.6
Fixed in:
3.10.7
Disclosed:
Apr 25, 2024

CVE-2024-3890 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.5

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.4.

Affected:
up to 3.10.5
Fixed in:
3.10.5
Disclosed:
Apr 22, 2024

CVE-2024-32698 on NVD →

Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scrip...

CVSS:
6.4
Affected:
up to 3.10.4
Fixed in:
3.10.5
Disclosed:
Apr 19, 2024

CVE-2024-32698 on NVD →

Happy Addons for Elementor <= 3.10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group, Photo Stack, & Horizontal Timeline

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Stack Group, Photo Stack, & Horizontal Timeline widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...

CVSS:
6.4
Affected:
up to 3.10.4
Fixed in:
3.10.5
Disclosed:
Apr 19, 2024

CVE-2024-3724 on NVD →

Happy Addons for Elementor <= 3.10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...

CVSS:
6.4
Affected:
up to 3.10.5
Fixed in:
3.10.6
Disclosed:
Apr 19, 2024

CVE-2024-3891 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.5

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

Affected:
up to 3.10.5
Fixed in:
3.10.5
Disclosed:
Apr 9, 2024

CVE-2024-2787 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.5

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization on the duplicate_thing() function in all versions up to, and including, 3.10.4. This makes it possible for attackers, with contributor-level access and above, to clone arbitrary posts...

Affected:
up to 3.10.5
Fixed in:
3.10.5
Disclosed:
Apr 9, 2024

CVE-2024-1387 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.5

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...

Affected:
up to 3.10.5
Fixed in:
3.10.5
Disclosed:
Apr 9, 2024

CVE-2024-2789 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.4

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on the title_tag attribute. This makes it possible for authenticated attackers, with contribut...

Affected:
up to 3.10.4
Fixed in:
3.10.4
Disclosed:
Apr 9, 2024

CVE-2024-2786 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.5

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

Affected:
up to 3.10.5
Fixed in:
3.10.5
Disclosed:
Apr 9, 2024

CVE-2024-2788 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.4

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...

Affected:
up to 3.10.4
Fixed in:
3.10.4
Disclosed:
Apr 9, 2024

CVE-2024-1498 on NVD →

Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title HTML Tag

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...

CVSS:
6.4
Affected:
up to 3.10.4
Fixed in:
3.10.5
Disclosed:
Apr 4, 2024

CVE-2024-2788 on NVD →

Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title HTML Tag

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...

CVSS:
6.4
Affected:
up to 3.10.4
Fixed in:
3.10.5
Disclosed:
Apr 4, 2024

CVE-2024-2787 on NVD →

Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Calendy

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with c...

CVSS:
6.4
Affected:
up to 3.10.4
Fixed in:
3.10.5
Disclosed:
Apr 4, 2024

CVE-2024-2789 on NVD →

Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Stack Widget

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers wit...

CVSS:
6.4
Affected:
up to 3.10.3
Fixed in:
3.10.4
Disclosed:
Apr 4, 2024

CVE-2024-1498 on NVD →

Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via title_tag

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on the title_tag attribute. This makes it possible for authenticated attackers, with contributor-le...

CVSS:
5.4
Affected:
up to 3.10.4
Fixed in:
3.10.5
Disclosed:
Apr 4, 2024

CVE-2024-2786 on NVD →

Happy Addons for Elementor <= 3.10.4 - Incorrect Authorization to Information Exposure

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization on the duplicate_thing() function in all versions up to, and including, 3.10.4. This makes it possible for attackers, with contributor-level access and above, to clone arbitrary posts (incl...

CVSS:
4.3
Affected:
up to 3.10.4
Fixed in:
3.10.5
Disclosed:
Apr 4, 2024

CVE-2024-1387 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.1.

Affected:
up to 3.10.2
Fixed in:
3.10.2
Disclosed:
Mar 19, 2024

CVE-2024-29108 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.4

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_tag’ attribute of the Archive Title widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...

Affected:
up to 3.10.4
Fixed in:
3.10.4
Disclosed:
Mar 7, 2024

CVE-2024-1366 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.4

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

Affected:
up to 3.10.4
Fixed in:
3.10.4
Disclosed:
Mar 7, 2024

CVE-2024-1377 on NVD →

Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Archive Title Widget

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_tag’ attribute of the Archive Title widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

CVSS:
6.4
Affected:
up to 3.10.3
Fixed in:
3.10.4
Disclosed:
Mar 6, 2024

CVE-2024-1366 on NVD →

Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Author Meta Widget

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 3.10.3
Fixed in:
3.10.4
Disclosed:
Mar 6, 2024

CVE-2024-1377 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.2

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributo...

Affected:
up to 3.10.2
Fixed in:
3.10.2
Disclosed:
Feb 20, 2024

CVE-2024-0438 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.2

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contrib...

Affected:
up to 3.10.2
Fixed in:
3.10.2
Disclosed:
Feb 20, 2024

CVE-2024-0838 on NVD →

Happy Addons for Elementor <= 3.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor acc...

CVSS:
6.4
Affected:
up to 3.10.1
Fixed in:
3.10.2
Disclosed:
Feb 13, 2024

CVE-2024-0438 on NVD →

Happy Addons for Elementor <= 3.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor...

CVSS:
6.4
Affected:
up to 3.10.1
Fixed in:
3.10.2
Disclosed:
Feb 13, 2024

CVE-2024-0838 on NVD →

Happy Addons for Elementor <= 3.10.1 - Missing Authorization via add_row_actions

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the add_row_actions() function in versions up to, and including, 3.10.1. This makes it possible for authenticated attackers, with contributor-level access and above, to clone arbitrary p...

CVSS:
4.3
Affected:
up to 3.10.1
Fixed in:
3.10.2
Disclosed:
Feb 2, 2024

CVE-2024-24833 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.0

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a...

Affected:
up to 3.10.0
Fixed in:
3.10.0
Disclosed:
Jan 11, 2024

CVE-2023-6632 on NVD →

Happy Elementor Addons <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AGe Gate Widget in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on the user supplied header URL value. This makes it possible for authenticated attack...

CVSS:
6.4
Affected:
up to 3.10.0
Fixed in:
3.10.1
Disclosed:
Jan 9, 2024

Happy Addons for Elementor [happy-elementor-addons] < 3.10.1

unknown

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AGe Gate Widget in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on the user supplied header URL value. This makes it possible for authenticated attack...

Affected:
up to 3.10.1
Fixed in:
3.10.1
Disclosed:
Jan 9, 2024

Happy Addons for Elementor <= 3.9.1.1 - Reflected Cross-Site Scripting

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attack...

CVSS:
6.1
Affected:
up to 3.9.1.1
Fixed in:
3.10.0
Disclosed:
Jan 5, 2024

CVE-2023-6632 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.0

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through 3.9.1.1.

Affected:
up to 3.10.0
Fixed in:
3.10.0
Disclosed:
Dec 29, 2023

CVE-2023-51676 on NVD →

Happy Addons for Elementor <= 3.9.1.1 - Server Side Request Forgery

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.10.0 (exclusive). This makes it possible for authenticated attackers, with contributor access and above, to make web requests to arbitrary locations originating from the web application and can be us...

CVSS:
5.4
Affected:
up to 3.10.0
Fixed in:
3.10.0
Disclosed:
Dec 27, 2023

CVE-2023-51676 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.8.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in weDevs Happy Addons for Elementor plugin <= 3.8.2 versions.

Affected:
up to 3.8.3
Fixed in:
3.8.3
Disclosed:
Jul 10, 2023

CVE-2023-28989 on NVD →

Happy Addons for Elementor <= 3.8.2 - Cross-Site Request Forgery via handle_optin_optout()

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.2. This is due to missing nonce validation on the handle_optin_optout() function. This makes it possible for unauthenticated attackers to modify optin and optout settings, via a forged r...

CVSS:
4.3
Affected:
up to 3.8.2
Fixed in:
3.8.3
Disclosed:
Mar 29, 2023

CVE-2023-28989 on NVD →

Appsero <= 1.2.1 - Missing Authorization

medium

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissio...

CVSS:
4.3
Affected:
up to 3.8.2
Fixed in:
3.8.3
Disclosed:
Dec 16, 2022

Appsero <= 1.2.0 - Cross-Site Request Forgery

medium

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...

CVSS:
4.3
Affected:
up to 3.8.2
Fixed in:
3.8.3
Disclosed:
Dec 14, 2022

CVE-2022-47150 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 2.24.0

unknown

[en] The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_...

Affected:
up to 2.24.0
Fixed in:
2.24.0
Disclosed:
May 17, 2021

CVE-2021-24292 on NVD →

Happy Addons for Elementor <= 2.23.0 & Pro Version < 1.17.0 - Stored Cross-Site Scripting

medium

The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_tag”...

CVSS:
6.4
Affected:
up to 2.24.0
Fixed in:
2.24.0
Disclosed:
Apr 26, 2021

CVE-2021-24292 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.12.3

unknown

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin&#039;s bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...

Affected:
up to 3.12.3
Fixed in:
3.12.3

Happy Addons for Elementor [happy-elementor-addons] < 3.8.0

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 3.8.0
Fixed in:
3.8.0

CVE-2022-47150 on NVD →

Happy Addons for Elementor [happy-elementor-addons] < 3.10.1

unknown

The plugin is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s AGe Gate Widget in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on the user supplied header URL value. This makes it possible for authenticated attackers with contributor-level and above...

Affected:
up to 3.10.1
Fixed in:
3.10.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database