plugin

Happy Elementor Addons Pro Vulnerabilities

6 known security issues reported for the Happy Elementor Addons Pro WordPress plugin. Most recent disclosed Jan 11, 2024.

3 medium

Running Happy Elementor Addons Pro on your site? Check whether your installed version is affected.

Scan your site free

Happy Addons for Elementor Pro [happy-elementor-addons-pro] < 2.10.0

unknown

[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a...

Affected:
up to 2.10.0
Fixed in:
2.10.0
Disclosed:
Jan 11, 2024

CVE-2023-6632 on NVD →

Happy Addons for Elementor <= 3.9.1.1 - Reflected Cross-Site Scripting

medium

The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attack...

CVSS:
6.1
Affected:
up to 2.9.1.1
Fixed in:
2.10.0
Disclosed:
Jan 5, 2024

CVE-2023-6632 on NVD →

Happy Addons for Elementor Pro [happy-elementor-addons-pro] < 2.8.1

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Happy addons Happy Elementor Addons Pro plugin <= 2.8.0 versions.

Affected:
up to 2.8.1
Fixed in:
2.8.1
Disclosed:
Sep 27, 2023

CVE-2023-41236 on NVD →

Happy Elementor Addons Pro <= 2.8.0 - Reflected Cross-Site Scripting

medium

The Happy Elementor Addons Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

CVSS:
6.1
Affected:
up to 2.8.0
Fixed in:
2.8.1
Disclosed:
Aug 29, 2023

CVE-2023-41236 on NVD →

Happy Addons for Elementor Pro [happy-elementor-addons-pro] < 1.17.0

unknown

[en] The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_...

Affected:
up to 1.17.0
Fixed in:
1.17.0
Disclosed:
May 17, 2021

CVE-2021-24292 on NVD →

Happy Addons for Elementor <= 2.23.0 & Pro Version < 1.17.0 - Stored Cross-Site Scripting

medium

The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_tag”...

CVSS:
6.4
Affected:
up to 1.17.0
Fixed in:
1.17.0
Disclosed:
Apr 26, 2021

CVE-2021-24292 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database