Happy Addons for Elementor Pro [happy-elementor-addons-pro] < 2.10.0
unknown
[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a...
- Affected:
- up to 2.10.0
- Fixed in:
- 2.10.0
- Disclosed:
- Jan 11, 2024
CVE-2023-6632 on NVD →
Happy Addons for Elementor <= 3.9.1.1 - Reflected Cross-Site Scripting
medium
The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attack...
- CVSS:
- 6.1
- Affected:
- up to 2.9.1.1
- Fixed in:
- 2.10.0
- Disclosed:
- Jan 5, 2024
CVE-2023-6632 on NVD →
Happy Addons for Elementor Pro [happy-elementor-addons-pro] < 2.8.1
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Happy addons Happy Elementor Addons Pro plugin <= 2.8.0 versions.
- Affected:
- up to 2.8.1
- Fixed in:
- 2.8.1
- Disclosed:
- Sep 27, 2023
CVE-2023-41236 on NVD →
Happy Elementor Addons Pro <= 2.8.0 - Reflected Cross-Site Scripting
medium
The Happy Elementor Addons Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...
- CVSS:
- 6.1
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.1
- Disclosed:
- Aug 29, 2023
CVE-2023-41236 on NVD →
Happy Addons for Elementor Pro [happy-elementor-addons-pro] < 1.17.0
unknown
[en] The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_...
- Affected:
- up to 1.17.0
- Fixed in:
- 1.17.0
- Disclosed:
- May 17, 2021
CVE-2021-24292 on NVD →
Happy Addons for Elementor <= 2.23.0 & Pro Version < 1.17.0 - Stored Cross-Site Scripting
medium
The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_tag”...
- CVSS:
- 6.4
- Affected:
- up to 1.17.0
- Fixed in:
- 1.17.0
- Disclosed:
- Apr 26, 2021
CVE-2021-24292 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database