{"error":0,"message":null,"data":{"name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates","plugin":"happy-elementor-addons","link":"https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/","latest":"1789643760","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"dc1052d5bc108dd7eb5fc80436e56c94b096b1eba35466bab67f1dc16fb56f08","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 2.24.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.24.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24292","name":"CVE-2021-24292","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24292","description":"[en] The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The \u201cCard\u201d widget accepts a \u201ctitle_tag\u201d parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a \u2018save_builder\u2019 request with the \u201cheading_tag\u201d set to \u201cscript\u201d, and the actual \u201ctitle\u201d parameter set to JavaScript to be executed within the script tags added by the \u201cheading_tag\u201d parameter.","date":"2021-05-17"},{"id":"76a35b09858be40ccc3f61d005bba517f750d09f","name":"Happy Addons for Elementor <= 2.23.0 & Pro Version < 1.17.0 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/happy-addons-for-elementor-2230-pro-version-1170-stored-cross-site-scripting","description":"The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The \u201cCard\u201d widget accepts a \u201ctitle_tag\u201d parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a \u2018save_builder\u2019 request with the \u201cheading_tag\u201d set to \u201cscript\u201d, and the actual \u201ctitle\u201d parameter set to JavaScript to be executed within the script tags added by the \u201cheading_tag\u201d parameter.","date":"2021-04-26"},{"id":"0f20e098-8106-451f-9448-d35a79f03077","name":"Happy Addons for Elementor Free &lt; 2.24.0 and Pro &lt; 1.17.0 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/0f20e098-8106-451f-9448-d35a79f03077","description":"The plugins have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The &ldquo;Card&rdquo; widget accepts a &ldquo;title_tag&rdquo; parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a &lsquo;save_builder&rsquo; request with the &ldquo;heading_tag&rdquo; set to &ldquo;script&rdquo;, and the actual &ldquo;title&rdquo; parameter set to JavaScript to be executed within the script tags added by the &ldquo;heading_tag&rdquo; parameter. \r\n\r\nThis JavaScript will then be executed when the saved page is viewed or previewed.\r\n\r\nThe other widgets that appear to be exploitable in this manner are:\r\n\r\nfun-factor: &quot;title_tag&quot; script tag + Javascript in &quot;fun_factor_title&quot; parameter\r\n\r\ngradient-heading: &quot;title_tag&quot; script tag + Javascript in &quot;title&quot; parameter\r\n\r\nicon-box: &quot;title_tag&quot; script tag + Javascript in &quot;title&quot; parameter\r\n\r\ninfobox: &quot;title_tag&quot; script tag + Javascript in &quot;title&quot; parameter\r\n\r\nmember: &quot;title_tag&quot; script tag + Javascript in &quot;title&quot; parameter\r\n\r\npost-list: &quot;title_tag&quot; script tag + Javascript in &quot;title&quot; parameter\r\n\r\nreview: &quot;title_tag&quot; script tag + Javascript in &quot;title&quot; parameter\r\n\r\nstep-flow: &quot;title_tag&quot; script tag + Javascript in &quot;title&quot; parameter\r\n\r\nThese vulnerabilities are nearly identical to the vulnerabilities we have recently disclosed in the main Elementor plugin: https:\/\/www.wordfence.com\/blog\/2021\/03\/cross-site-scripting-vulnerabilities-in-elementor-impact-over-7-million-sites\/","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"425fde4fb60856c3a7afe40af51cf2a442a2aa11dde93a68428e86302e24cb92","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.8.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-47150","name":"CVE-2022-47150","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-47150","description":"[en] Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forgery.\n\nThis issue affects WooCommerce Conversion Tracking: from n\/a through 2.0.10.","date":"2026-06-11"},{"id":"0bdbe491fb06c3835a7a20a67e2f83f96de12226","name":"WordPress  Happy Addons for Elementor Plugin  <= 3.7.2 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-7-2-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.8.0).\nLana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.8.0.","date":"2023-03-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0182848b51e02d9363db6e65fab0ea0d60a7f092ded8215b8fa45285bd2a6f6c","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-28989","name":"CVE-2023-28989","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-28989","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in weDevs Happy Addons for Elementor plugin <=\u00a03.8.2 versions.","date":"2023-07-10"},{"id":"c279519647963e1abbc7fb551b53bf2abdfc26a9","name":"WordPress  Happy Addons for Elementor Plugin  <= 3.8.2 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-8-2-cross-site-request-forgery-csrf-on-collect-data-popup","description":"Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.8.3).\nMuhammad Daffa discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.8.3.","date":"2023-03-29"},{"id":"98124d7e0476396787c548135ecda99421ec2295","name":"Happy Addons for Elementor <= 3.8.2 - Cross-Site Request Forgery via handle_optin_optout()","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-382-cross-site-request-forgery-via-handle-optin-optout","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.2. This is due to missing nonce validation on the handle_optin_optout() function. This makes it possible for unauthenticated attackers to modify optin and optout settings, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-03-29"},{"id":"fe292389-0b47-4fdf-9d58-1131ea17800a","name":"Happy Addons for Elementor &lt; 3.8.3 - Cross-Site Request Forgery","link":"https:\/\/wpscan.com\/vulnerability\/fe292389-0b47-4fdf-9d58-1131ea17800a","description":"Cross-Site Request Forgery (CSRF) vulnerability in weDevs Happy Addons for Elementor plugin &lt;=&nbsp;3.8.2 versions.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4c32024ccbbabd02cef92ef2973cb53722e1d07c44eda8a781ca7cef39799146","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-51676","name":"CVE-2023-51676","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-51676","description":"[en] Server-Side Request Forgery (SSRF) vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n\/a through 3.9.1.1.","date":"2023-12-29"},{"id":"5e9ba046187e7e910187e2668e1a64bc932ea790","name":"WordPress  Happy Addons for Elementor Plugin  <= 3.9.1.1 is vulnerable to Server Side Request Forgery (SSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-9-1-1-server-side-request-forgery-ssrf-vulnerability","description":"Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.0).\nYuchen Ji discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system. This vulnerability has been fixed in version 3.10.0.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-27"},{"id":"83e592ecced1bdd676870005f1644eb100149df8","name":"Happy Addons for Elementor <= 3.9.1.1 - Server Side Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3911-server-side-request-forgery-ssrf","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.10.0 (exclusive). This makes it possible for authenticated attackers, with contributor access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.","date":"2023-12-27"},{"id":"565246ee-5122-4b60-83e9-0790cd7f3175","name":"Happy Addons for Elementor &lt; 3.10.0 - Contributor+ SSRF","link":"https:\/\/wpscan.com\/vulnerability\/565246ee-5122-4b60-83e9-0790cd7f3175","description":"The plugin is vulnerable to Server-Side Request Forgery, allowing authenticated attackers, with contributor access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"h","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"4.9","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"4.9","severity":"medium","av":"network","ac":"high","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-918","name":"Server-Side Request Forgery (SSRF)","description":"The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination."}]}},{"uuid":"276860c7536b30d11c0593853112aba3dc9c2a09cc1608e0770d13943535af73","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6632","name":"CVE-2023-6632","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6632","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-01-11"},{"id":"de5eba5eb7d1a0b4d17f3847258bc1a7c95f4589","name":"Happy Addons for Elementor <= 3.9.1.1 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/happy-addons-for-elementor-3911-reflected-cross-site-scripting","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-01-05"},{"id":"4188b6aa7ee46de1841872c66cff1e38491b5149","name":"WordPress  Happy Addons for Elementor Plugin  <= 3.9.1.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-9-1-1-reflected-cross-site-scripting-vulnerability","description":"Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.0).\nxEHLE discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.10.0.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-05"},{"id":"950e8791-3ca2-40a3-9c16-211e8ad290b2","name":"Happy Addons for Elementor (Free &lt; 3.10.0, Pro &lt; 2.10.0) - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/950e8791-3ca2-40a3-9c16-211e8ad290b2","description":"The plugins are vulnerable to Reflected Cross-Site Scripting via DOM due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b1a490813061b6301ca300857dd1fe4e52583968956f6bff6d64bb3ee9f1c470","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"19b1bf37778359f6a7c661e53860cf8e5852f827","name":"Happy Elementor Addons <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-elementor-addons-3100-authenticated-contributor-stored-cross-site-scripting","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AGe Gate Widget in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on the user supplied header URL value. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-01-09"}],"impact":[]},{"uuid":"33ec8d2c2686b9c25e82b062361aaf80133ac3e2298436febf10d2c1b9d62b1a","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-24833","name":"CVE-2024-24833","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-24833","description":"[en] Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for Elementor: from n\/a through <= 3.10.1.","date":"2024-05-08"},{"id":"0afb90dfa3d7f4d8c9c60b758ef2610b804f8aba","name":"Happy Addons for Elementor <= 3.10.1 - Missing Authorization via add_row_actions","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3101-missing-authorization-via-add-row-actions","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the add_row_actions() function in versions up to, and including, 3.10.1. This makes it possible for authenticated attackers, with contributor-level access and above, to clone arbitrary posts, including password protected posts which may allow them to access the restricted posts content.","date":"2024-02-02"},{"id":"23e8a640275bbb952e946899f55dc562c45ae548","name":"WordPress  Happy Addons for Elementor Plugin  <= 3.10.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-10-1-broken-access-control-on-post-clone-vulnerability","description":"Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.2).\nAbu Hurayra discovered and reported this Broken Access Control vulnerability in WordPress Happy Addons for Elementor Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.10.2.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"cf2bd6aa-4211-4c2e-bfa2-6c8a6a3b02d0","name":"Happy Addons for Elementor &lt; 3.10.2 - Missing Authorization via add_row_actions","link":"https:\/\/wpscan.com\/vulnerability\/cf2bd6aa-4211-4c2e-bfa2-6c8a6a3b02d0","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the add_row_actions() function in versions up to, and including, 3.10.1. This makes it possible for authenticated attackers, with contributor-level access and above, to clone arbitrary posts, including password protected posts which may allow them to access the restricted posts content.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f9b290b7c8eaa19ee8cbf7b8f96194abced3688cf580b15a1107a388c7c8c32c","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-0438","name":"CVE-2024-0438","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-0438","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-20"},{"id":"5e6cfe878170fd72f2ffed57bf8dd3a6d4a59c80","name":"Happy Addons for Elementor <= 3.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3101-authenticated-contributor-stored-cross-site-scripting","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-29108 is likely a duplicate of this issue.","date":"2024-02-13"},{"id":"923efa24a4da0350b6f6d890f75ae9646cea1610","name":"WordPress  Happy Addons for Elementor Plugin    <= 3.10.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-10-1-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.2).\nwesley (wcraft) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.10.2.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"0203d351-c719-4f5d-9130-0369b993847d","name":"Happy Addons for Elementor &lt; 3.10.2 - Contributor+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/0203d351-c719-4f5d-9130-0369b993847d","description":"The plugin does not properly sanitize the wrapper link parameter in the Age Gate, allowing users with at least the contributor access to conduct Stored XSS attacks.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"26b5a11a12e48789201f1bccd93eaf0a7696797b9e89d4ff3797d57b19297cab","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-0838","name":"CVE-2024-0838","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-0838","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-02-20"},{"id":"1ffc355dae2eb303b1c40a2406f87a2efcda7eda","name":"Happy Addons for Elementor <= 3.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3101-authenticated-contributor-stored-cross-site-scripting-1","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-29108 is likely a duplicate of this issue.","date":"2024-02-13"},{"id":"bf5c24ca-b240-492c-93cd-cad96d63daaa","name":"Happy Addons for Elementor &lt; 3.10.2 - Contributor+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/bf5c24ca-b240-492c-93cd-cad96d63daaa","description":"The does not properly sanitize the side image URL parameter in the Age Gate, allowing users with at least thhe contributor role to conduct Stored XSS attacks.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2c96c44192f139497ad1de9c3c0967d34dca4e11dd328b0c43b7bdbbc454dc02","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1377","name":"CVE-2024-1377","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1377","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018author_meta_tag\u2019 attribute of the Author Meta widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-07"},{"id":"c15ab76b2a8ec78e288196e53b33a00e09a4086f","name":"Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Author Meta Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3103-authenticated-contributor-stored-cross-site-scripting-via-author-meta-widget","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018author_meta_tag\u2019 attribute of the Author Meta widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-06"},{"id":"c83a9b0615c0a37b6be830df3a103f4cafb327aa","name":"WordPress  Happy Addons for Elementor Plugin    <= 3.10.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-10-3-authenticated-contributor-stored-cross-site-scripting-via-author-meta-widget-vulnerability","description":"Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.4).\nNikolas discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.10.4.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"35c3a8f5-60e7-4a7d-beb6-a3b267e57972","name":"Happy Addons for Elementor &lt; 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Author Meta Widget","link":"https:\/\/wpscan.com\/vulnerability\/35c3a8f5-60e7-4a7d-beb6-a3b267e57972","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &lsquo;author_meta_tag&rsquo; attribute of the Author Meta widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9de8a294c0ede47c76923099b4d7183dcac4e776fdb70726e02b5d4fbb304eeb","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1366","name":"CVE-2024-1366","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1366","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018archive_title_tag\u2019 attribute of the Archive Title widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-07"},{"id":"9f59ece5e7a7a847ea9e504d9d7ae582dc41b110","name":"Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Archive Title Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3103-authenticated-contributor-stored-cross-site-scripting-via-archive-title-widget","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018archive_title_tag\u2019 attribute of the Archive Title widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-06"},{"id":"98b0b95e4e10d0f019aaf24c8960b9dea398ed32","name":"WordPress  Happy Addons for Elementor Plugin    <= 3.10.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-10-3-authenticated-contributor-stored-cross-site-scripting-via-archive-title-widget-vulnerability","description":"Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.4).\nwesley (wcraft) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.10.4.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"19ad6e0c-5f85-42c4-9161-69934baf9a97","name":"Happy Addons for Elementor &lt; 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Archive Title Widget","link":"https:\/\/wpscan.com\/vulnerability\/19ad6e0c-5f85-42c4-9161-69934baf9a97","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &lsquo;archive_title_tag&rsquo; attribute of the Archive Title widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1d3600ac76f719aafaa6075b26b8f35193dec0cadd428bda1682370b66a41eae","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-29108","name":"CVE-2024-29108","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-29108","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n\/a through 3.10.1.","date":"2024-03-19"},{"id":"d7679d8daff60728f445defadd3e3046265098a9","name":"WordPress  Happy Addons for Elementor Plugin    <= 3.10.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-10-1-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.2).\nAbu Hurayra discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.10.2.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"09ce74ff5f55bdf7952e3251c6e0a27b9cc4c4b677b3bc30f8640182d0b9fdd1","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1387","name":"CVE-2024-1387","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1387","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization on the duplicate_thing() function in all versions up to, and including, 3.10.4. This makes it possible for attackers, with contributor-level access and above, to clone arbitrary posts (including private and password protected ones) which may lead to information exposure.","date":"2024-04-09"},{"id":"3ee49918ddeee2fc9186877c267bf2e78168f2af","name":"Happy Addons for Elementor <= 3.10.4 - Incorrect Authorization to Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3104-incorrect-authorization-to-information-exposure","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization on the duplicate_thing() function in all versions up to, and including, 3.10.4. This makes it possible for attackers, with contributor-level access and above, to clone arbitrary posts (including private and password protected ones) which may lead to information exposure.","date":"2024-04-04"},{"id":"54dc57e74e15e011920e47c5e1ef8a1747e3fb18","name":"WordPress Happy Addons for Elementor Plugin <= 3.10.4 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-10-4-incorrect-authorization-to-information-exposure-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.10.4 is vulnerable to Sensitive Data Exposure<\/p><p>Software: Happy Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/#developers<\/p><p>Affected Version <= 3.10.4<\/p><p>Fixed in version 3.10.5 <\/p>","date":"2024-04-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"82a54463042b5859a2c6bcd62e1b89ef6a6bb4390b661a97976577ec3955c1bb","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2789","name":"CVE-2024-2789","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2789","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-09"},{"id":"3fe83c04c90fe95de36ab37114d2ed1b86bf29aa","name":"Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Calendy","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3104-authenticated-contributor-stored-cross-site-scripting-via-calendy","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"22ca94de82f30d2dd41d245d582cf55e6d02c414f8ab69510e777f408cca6844","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2786","name":"CVE-2024-2786","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2786","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on the title_tag attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-09"},{"id":"a63776fdaa6285d6de3514e7f553f5af7253417c","name":"Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via title_tag","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3104-authenticated-contributor-dom-based-stored-cross-site-scripting-via-title-tag","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on the title_tag attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"cfb76b1a7bd8389df7a76ac044911c2c62baadfc7cb37da2be898516ff036e03","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2788","name":"CVE-2024-2788","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2788","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-09"},{"id":"a9bc0eef5d624671e84a68501d0c5520f25b10f1","name":"Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title HTML Tag","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3104-authenticated-contributor-stored-cross-site-scripting-via-post-title-html-tag","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32698 is likely a duplicate of this issue.","date":"2024-04-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"dab6e8f65376047cf973f4efe8e41dc7e15b8519c047711e435bc7abbea63bf8","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1498","name":"CVE-2024-1498","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1498","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-09"},{"id":"488e8a5ba47797a6c477c414714257ec33cef3c8","name":"Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Stack Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3103-authenticated-contributor-stored-cross-site-scripting-via-photo-stack-widget","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"56f29ffe3a94d58bcf5fef6f77bee2cf7b95e53c9edc1460e4e238c80d0f8f0b","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2787","name":"CVE-2024-2787","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2787","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-09"},{"id":"aecf0d685b47c19cb80e9d977408a4eab7c523ff","name":"Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title HTML Tag","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3104-authenticated-contributor-stored-cross-site-scripting-via-page-title-html-tag","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"42136740a9be2510a8fafa9fdab810d4e17634991a2af6b994db6c55f2eefad2","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3724","name":"CVE-2024-3724","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3724","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Stack Group, Photo Stack, & Horizontal Timeline widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-02"},{"id":"843342a389d527171aa81f790b85dcf7d265e861","name":"Happy Addons for Elementor <= 3.10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group, Photo Stack, & Horizontal Timeline","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3105-authenticated-contributor-stored-cross-site-scripting-via-image-stack-group-photo-stack-horizontal-timeline","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Stack Group, Photo Stack, & Horizontal Timeline widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c4e204f76dc2813c5d2aca1cc53111b6fe9ca8dd0ffdf571d2ce3d7cadad71c0","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3891","name":"CVE-2024-3891","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3891","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-02"},{"id":"bfd60d8b89093916f1dcb737148c4e1dc60530ec","name":"Happy Addons for Elementor <= 3.10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3105-authenticated-contributor-stored-cross-site-scripting-via-html-tags","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-19"},{"id":"d6891a9f1b3d524f8d1bef1f0b6ecc5488ad4853","name":"WordPress Happy Addons for Elementor Plugin <= 3.10.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-10-5-authenticated-contributor-stored-cross-site-scripting-via-html-tags-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.10.5 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Happy Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/#developers<\/p><p>Affected Version <= 3.10.5<\/p><p>Fixed in version 3.10.6 <\/p>","date":"2024-04-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8ea9733ec55c59602ee7dbc53d0160f36b23f83c2a935d87bef354acecf2e51c","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-32698","name":"CVE-2024-32698","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-32698","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for Elementor: from n\/a through <= 3.10.4.","date":"2024-04-22"},{"id":"3fba289b443859ed144455dc62370b910eefa167","name":"WordPress Happy Addons for Elementor Plugin <= 3.10.4 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-10-4-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.10.4 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Happy Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/#developers<\/p><p>Affected Version <= 3.10.4<\/p><p>Fixed in version 3.10.5 <\/p>","date":"2024-04-19"},{"id":"75cb2c74ce261c9d54cf06266c3f7163de7265aa","name":"Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3104-authenticated-contributor-stored-cross-site-scripting","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6a788a73080f4bb5af016da0a863b1e920476fbddf363709bc82105a17fc726f","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3890","name":"CVE-2024-3890","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3890","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-26"},{"id":"2ecdfdce938389ed330b79c045709b01f22018c8","name":"Happy Addons for Elementor <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Calendly Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3106-authenticated-contributor-stored-cross-site-scripting-via-calendly-widget","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-25"},{"id":"b6d23f56f90adc47b4a2d8a859c396c18a4ff0a1","name":"WordPress Happy Addons for Elementor Plugin <= 3.10.6 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-10-6-authenticated-contributor-stored-cross-site-scripting-via-calendly-widget-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.10.6 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Happy Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/#developers<\/p><p>Affected Version <= 3.10.6<\/p><p>Fixed in version 3.10.7 <\/p>","date":"2024-04-26"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"bd528096648ba322c0ba3ec0c7a574625aecef60836589e87c85bb2c7c8fc2f3","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4478","name":"CVE-2024-4478","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4478","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied 'tooltip_position' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-16"},{"id":"42b3dfb69e8922a112a14b6bd076b763643f7261","name":"WordPress Happy Addons for Elementor Plugin <= 3.10.7 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-10-7-authenticated-contributor-stored-cross-site-scripting-via-image-stack-group-widget-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.10.7 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Happy Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/#developers<\/p><p>Affected Version <= 3.10.7<\/p><p>Fixed in version 3.10.8 <\/p>","date":"2024-05-16"},{"id":"61e3442dd30a8d294b08acc8c67509160f608cef","name":"Happy Addons for Elementor <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3107-authenticated-contributor-stored-cross-site-scripting-via-image-stack-group-widget","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied 'tooltip_position' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"bdcf7a6f1b50b6c2036073721971b9deeb55cee28c16cc414b65d7ee7d888f01","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4391","name":"CVE-2024-4391","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4391","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-16"},{"id":"5e22d9886ed26983d4504af564f87e05b143a30f","name":"Happy Addons for Elementor Authenticated (Contributor+) Stored-XSS <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-authenticated-contributor-stored-xss-3107-authenticated-contributor-stored-cross-site-scripting-via-event-calendar-widget","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3537d283ecb57abcdd9acc9a0ba56898f2e445357d686c95c3bd55c4b751c28c","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4865","name":"CVE-2024-4865","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4865","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018_id\u2019 parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-18"},{"id":"248182d7f72ded8b8ef3e3b746e1fa23ef30c78e","name":"Happy Addons for Elementor <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via _id Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3108-authenticated-contributor-stored-cross-site-scripting-via-id-parameter","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018_id\u2019 parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-17"},{"id":"8330914170bf34811502f2eeb64af35f6cb40d1f","name":"WordPress Happy Addons for Elementor Plugin <= 3.10.8 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-10-8-authenticated-contributor-stored-cross-site-scripting-via-id-parameter-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.10.8 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Happy Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/#developers<\/p><p>Affected Version <= 3.10.8<\/p><p>Fixed in version 3.10.9 <\/p>","date":"2024-05-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5c647f52066d8f9cd438d6601c37135fb87aa45176221958e589a14539dd0f9f","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5088","name":"CVE-2024-5088","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5088","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018_id\u2019 parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-18"},{"id":"96047c2007c6e6985f06c38b76e24409d29e073f","name":"Happy Addons for Elementor <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3108-authenticated-contributor-stored-cross-site-scripting","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018_id\u2019 parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5ee28f40130899897ccdb3e9c2367ebd8e49708cbe883c321c8da3c94639e049","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.11.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.11.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5041","name":"CVE-2024-5041","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5041","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018ha-ia-content-button\u2019 parameter in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-31"},{"id":"cb41f3c55f6c04fd6a90fa1c08f71c3bb97c7822","name":"Happy Addons for Elementor <= 3.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3109-authenticated-contributor-stored-cross-site-scripting-via-image-accordion","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018ha-ia-content-button\u2019 parameter in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"25ef763535ae3d096b728832adabca7cf10621a6f6c6c06850384f49a7a8c606","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.11.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.11.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5347","name":"CVE-2024-5347","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5347","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-31"},{"id":"a71cda04ff4553c6fc8f7f4fe0a71222dd59171e","name":"WordPress Happy Addons for Elementor Plugin <= 3.10.9 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-10-9-authenticated-contributor-stored-cross-site-scripting-via-post-navigation-widget-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.10.9 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Happy Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/#developers<\/p><p>Affected Version <= 3.10.9<\/p><p>Fixed in version 3.11.0 <\/p>","date":"2024-05-31"},{"id":"2e229c0f0a6ad75dee9885767203ae2e47f41f12","name":"Happy Addons for Elementor <= 3.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3109-authenticated-contributor-stored-cross-site-scripting-via-post-navigation-widget","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7ad13427299b5b2e47bf1dba5d3bf265cad7c8eca8c274b0719f3f9b992c35a3","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.11.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.11.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5790","name":"CVE-2024-5790","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5790","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018url\u2019 attribute within the plugin's Gradient Heading widget in all versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-29"},{"id":"f910f08cb86b6e824d75a8a42607483544091199","name":"Happy Addons for Elementor <= 3.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gradient Heading Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3111-authenticated-contributor-stored-cross-site-scripting-via-gradient-heading-widget","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018url\u2019 attribute within the plugin's Gradient Heading widget in all versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-28"},{"id":"416fb95660157096c5d302a119bf1668785b7da6","name":"WordPress Happy Addons for Elementor Plugin <= 3.11.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-11-1-authenticated-contributor-stored-cross-site-scripting-via-gradient-heading-widget-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.11.1 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Happy Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/#developers<\/p><p>Affected Version <= 3.11.1<\/p><p>Fixed in version 3.11.2 <\/p>","date":"2024-07-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"909222178cc771c8d41b8a1b46e32e9955353524029ecbd3f80a4e44ea3d73d0","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.10.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2bc1433c-6129-48f7-9d0a-84b5c680a6d1","name":"Happy Elementor Addons &lt; 3.10.1 - Contributor+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/2bc1433c-6129-48f7-9d0a-84b5c680a6d1","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s AGe Gate Widget in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on the user supplied header URL value. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":[]},{"uuid":"9540ae71785faaf0ba195a69d74aa1206d270efbdb9833d3f399075b05f18a27","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.11.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.11.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6627","name":"CVE-2024-6627","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6627","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-07-27"},{"id":"6f14a1616f2218bec4c6e68c9b498b3ae28ba21a","name":"Happy Addons for Elementor <= 3.11.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via PDF View Widget","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3112-authenticated-contributor-stored-cross-site-scripting-via-pdf-view-widget","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-07-26"},{"id":"81bd5486337887a8c7d4353af0d9f45a1ef1a4cf","name":"WordPress Happy Addons for Elementor Plugin <= 3.11.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-11-2-authenticated-contributor-stored-cross-site-scripting-via-pdf-view-widget-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.11.2 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Happy Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/#developers<\/p><p>Affected Version <= 3.11.2<\/p><p>Fixed in version 3.11.3 <\/p>","date":"2024-07-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1629b11a8b881c0229b1a8c2b17c972b6a4fef0af4a95a7963095addaff05cbb","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.12.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.12.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8801","name":"CVE-2024-8801","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8801","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including private, draft, and pending Elementor templates.","date":"2024-09-24"},{"id":"7ce2d666690f02f69ffaf25ffa10262c43095d9e","name":"Happy Addons for Elementor <= 3.12.2 - Authenticated (Contributor+) Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3122-authenticated-contributor-sensitive-information-exposure","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including private, draft, and pending Elementor templates.","date":"2024-09-23"},{"id":"e18dee0f141f5e9d122e8146b0009671af535510","name":"WordPress Happy Addons for Elementor Plugin <= 3.12.2 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-12-2-authenticated-contributor-sensitive-information-exposure-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.12.2 is vulnerable to Sensitive Data Exposure<\/p><p>Software: Happy Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/#developers<\/p><p>Affected Version <= 3.12.2<\/p><p>Fixed in version 3.12.3 <\/p>","date":"2024-09-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5d099ff7500b1d8b0fdaa18d2edc0fcfb255d6593df189e77bac578d966e4205","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.12.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.12.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-47357","name":"CVE-2024-47357","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-47357","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Stored XSS.This issue affects Happy Addons for Elementor: from n\/a through <= 3.12.0.","date":"2024-10-06"},{"id":"75c745649b76750cbd365a0badb23b7a04b47448","name":"WordPress Happy Addons for Elementor Plugin <= 3.12.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-12-0-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.12.0 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Happy Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/#developers<\/p><p>Affected Version <= 3.12.0<\/p><p>Fixed in version 3.12.1 <\/p>","date":"2024-09-30"},{"id":"b3d2925a4dfb220f1345242d65407dd1ffa06fe4","name":"Happy Addons for Elementor <= 3.12.0 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3120-authenticated-contributor-stored-cross-site-scripting","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-09-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e082f428901e0f634c2ec736c780eb1e19aa69a5440fa08153ff1743ac39691d","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.12.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.12.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-48045","name":"CVE-2024-48045","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-48045","description":"[en] Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy Addons for Elementor: from n\/a through <= 3.12.3.","date":"2024-11-01"},{"id":"94efb2a8a63b4ce1f67476289ba77be95d34aabc","name":"WordPress Happy Addons for Elementor Plugin <= 3.12.3 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-elementor-addons-plugin-3-12-3-broken-access-control-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.12.3 is vulnerable to Broken Access Control<\/p><p>Software: Happy Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/#developers<\/p><p>Affected Version <= 3.12.3<\/p><p>Fixed in version 3.12.4 <\/p>","date":"2024-10-13"},{"id":"a44e12e0a6345a14f697eb110b10508f1000f72f","name":"Happy Addons for Elementor <= 3.12.3 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3123-missing-authorization","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_reqeust() function in versions up to, and including, 3.12.3. This makes it possible for authenticated attackers, with contributor-level access and above, to view draft\/private\/password protected templates.","date":"2024-10-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"56558d5f3e4900f1de1096c345c71057b98eb40cc9f2684f599544a0c987e34b","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.12.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.12.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10538","name":"CVE-2024-10538","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10538","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.12.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-11-12"},{"id":"a5810076c0388749286d71f54935547f320ef4ce","name":"WordPress Happy Addons for Elementor Plugin <= 3.12.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-12-5-authenticated-contributor-stored-cross-site-scripting-via-image-comparison-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.12.5 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Happy Addons for Elementor<\/p><p>Link: https:\/\/wordpress.org\/plugins\/happy-elementor-addons\/#developers<\/p><p>Affected Version <= 3.12.5<\/p><p>Fixed in version 3.12.6 <\/p>","date":"2024-11-12"},{"id":"3dafd797f8d18288b0d2d0aee2d9d64c91277d4a","name":"Happy Addons for Elementor <= 3.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3125-authenticated-contributor-stored-cross-site-scripting-via-image-comparison","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.12.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-11-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8130b6e208192765812fad26b9943286008a2dd7648e20ba1b404287de2d43c2","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.15.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.15.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-12852","name":"CVE-2024-12852","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-12852","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-01-08"},{"id":"7f86c423ac9ba9db8fffdbe7567597ba7083e51b","name":"WordPress Happy Addons for Elementor Plugin <= 3.15.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/happy-elementor-addons\/vulnerability\/wordpress-happy-addons-for-elementor-plugin-3-15-1-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Happy Addons for Elementor Plugin <= 3.15.1 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Happy Addons for Elementor<\/p><p>Fixed in version 3.15.2 <\/p><p>Affected Version <= 3.15.1<\/p><p>CVE: CVE-2024-12852<\/p>","date":"2025-01-07"},{"id":"fd149d3487039fe40df0aff849fa0f633b33f8a3","name":"Happy Addons for Elementor <= 3.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3151-authenticated-contributor-stored-cross-site-scripting","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-01-07"},{"id":"EUVD-2024-51153","name":"EUVD-2024-51153","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-51153","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-01-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"bb417e41be11b525f1b0bf300d393206060c4d5f8de5c11a2fe8e63ddbd63da7","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.16.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.16.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-30766","name":"CVE-2025-30766","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-30766","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows DOM-Based XSS.This issue affects Happy Addons for Elementor: from n\/a through <= 3.16.2.","date":"2025-03-27"},{"id":"6ab24cb27613f8f9c915c938913302b96de2c98b","name":"Happy Addons for Elementor <= 3.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3162-authenticated-contributor-stored-cross-site-scripting","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.16.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-03-27"},{"id":"EUVD-2025-8407","name":"EUVD-2025-8407","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-8407","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor allows DOM-Based XSS. This issue affects Happy Addons for Elementor: from n\/a through 3.16.2.","date":"2025-03-27"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":null,"impact":null}}},{"uuid":"ea9e74280581cfa9d88de7c445154e984e62cc01db859042ccbe05cb7a54a8dc","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.12.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.12.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8fdec6763b3c730130b642406e93234959989593","name":"Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/multiple-plugins-various-versions-authenticated-contributor-stored-dom-based-cross-site-scripting-via-magnific-popups-javascript-library","description":"Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.","date":"2025-07-02"},{"id":"CVE-2024-5647","name":"CVE-2024-5647","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5647","description":"[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.","date":"2025-07-03"},{"id":"c2998af6-d000-4da5-a60d-dbc6e52474bf","name":"Magnific Popups JavaScript Library &lt; 1.2.0 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/c2998af6-d000-4da5-a60d-dbc6e52474bf","description":"Multiple plugins are vulnerable to Stored Cross-Site Scripting via the plugin&#039;s bundled Magnific Popups library (version 1.1.0) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.","date":"2025-07-02"},{"id":"EUVD-2024-54725","name":"EUVD-2024-54725","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-54725","description":"Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.","date":"2025-07-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"9c3f2bb9f2ba6e969f8ab468410ece76d04944262f4895737b45e0b25b342d65","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.20.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.20.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-63077","name":"CVE-2025-63077","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-63077","description":"[en] Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy Addons for Elementor: from n\/a through <= 3.20.3.","date":"2025-12-09"},{"id":"66b868e441bb16cd25f249707cde4110aca20034","name":"Happy Addons for Elementor <= 3.20.3 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3203-missing-authorization","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.20.3. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.","date":"2025-12-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"eccca67fb95a282a944a3bcb3958190654e7d5531fd844808f26f3881cb996d9","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.20.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.20.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-14635","name":"CVE-2025-14635","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-14635","description":"[en] The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom_js' parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, despite the intended role restriction of Custom JS to Administrators.","date":"2025-12-23"},{"id":"1a646280a1d49fbccb7b5d70cdd174da5ac6c6a7","name":"Happy Addons for Elementor <= 3.20.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3203-authenticated-contributor-stored-cross-site-scripting-via-custom-js","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom_js' parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, despite the intended role restriction of Custom JS to Administrators.","date":"2025-12-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c1bfd287bcb91405b1e2688d64ab261dc7ff222cbecc6a444256b1fb2ce16dce","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.20.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.20.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-68999","name":"CVE-2025-68999","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-68999","description":"[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Blind SQL Injection.This issue affects Happy Addons for Elementor: from n\/a through <= 3.20.4.","date":"2026-01-22"},{"id":"9f5aac06e998902aa92660d1eadcf860d492f240","name":"Happy Addons for Elementor <= 3.20.4 - Authenticated (Contributor+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3204-authenticated-contributor-sql-injection","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.20.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-01-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:N\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"h","i":"n","a":"l","score":"8.5","severity":"h","exploitable":"3.1","impact":"4.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:N\/A:L","score":"8.5","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"high","i":"none","a":"low","exploitable":"3.1","impact":"4.7"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"055ee1962924b3ba090f06796cbc518c715fd2af7415dec2c9e7649dd8277b20","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.21.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.21.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-2917","name":"Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2917","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate_thing` admin action handler. This is due to the `can_clone()` method only checking `current_user_can('edit_posts')` (a general capability) without performing object-level authorization such as `current_user_can('edit_post', $post_id)`, and the nonce being tied to the generic action name `ha_duplicate_thing` rather than to a specific post ID. This makes it possible for authenticated attackers, with Contributor-level access and above, to clone any published post, page, or custom post type by obtaining a valid clone nonce from their own posts and changing the `post_id` parameter to target other users' content. The clone operation copies the full post content, all post metadata (including potentially sensitive widget configurations and API tokens), and taxonomies into a new draft owned by the attacker.","date":"0000-00-00"},{"id":"10425fb4906d67a54d3df93e63ed043dd5cb3dfd","name":"Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3210-insecure-direct-object-reference-to-authenticated-contributor-post-duplication-via-post-id-parameter","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate_thing` admin action handler. This is due to the `can_clone()` method only checking `current_user_can('edit_posts')` (a general capability) without performing object-level authorization such as `current_user_can('edit_post', $post_id)`, and the nonce being tied to the generic action name `ha_duplicate_thing` rather than to a specific post ID. This makes it possible for authenticated attackers, with Contributor-level access and above, to clone any published post, page, or custom post type by obtaining a valid clone nonce from their own posts and changing the `post_id` parameter to target other users' content. The clone operation copies the full post content, all post metadata (including potentially sensitive widget configurations and API tokens), and taxonomies into a new draft owned by the attacker.","date":"2026-03-10"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"69df4190f1e9c7414b7e096e4f6aa69de753926a6546ee3e042a82e8ae50d8b6","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.21.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.21.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-2918","name":"Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2918","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_condition_update` AJAX action. This is due to the `validate_reqeust()` method using `current_user_can('edit_posts', $template_id)` instead of `current_user_can('edit_post', $template_id)` \u2014 failing to perform object-level authorization. Additionally, the `ha_get_current_condition` AJAX action lacks a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify the display conditions of any published `ha_library` template. Because the `cond_to_html()` renderer outputs condition values into HTML attributes without proper escaping (using string concatenation instead of `esc_attr()`), an attacker can inject event handler attributes (e.g., `onmouseover`) that execute JavaScript when an administrator views the Template Conditions panel, resulting in Stored Cross-Site Scripting.","date":"0000-00-00"},{"id":"2849ccc3e936e1595183439f38572e12cbc79c8c","name":"Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3210-insecure-direct-object-reference-to-authenticated-contributor-stored-cross-site-scripting-via-template-conditions","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_condition_update` AJAX action. This is due to the `validate_reqeust()` method using `current_user_can('edit_posts', $template_id)` instead of `current_user_can('edit_post', $template_id)` \u2014 failing to perform object-level authorization. Additionally, the `ha_get_current_condition` AJAX action lacks a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify the display conditions of any published `ha_library` template. Because the `cond_to_html()` renderer outputs condition values into HTML attributes without proper escaping (using string concatenation instead of `esc_attr()`), an attacker can inject event handler attributes (e.g., `onmouseover`) that execute JavaScript when an administrator views the Template Conditions panel, resulting in Stored Cross-Site Scripting.","date":"2026-03-10"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2c38d2fb77f7e5ea249c738ea2536821828ec2d4a7975a8f8d2656be4ec0b3df","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.20.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.20.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1210","name":"Happy Addons for Elementor <= 3.20.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_elementor_data' Meta Field","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1210","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_data' meta field in all versions up to, and including, 3.20.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"b8213f0c63428b3f11a7798e2d45a9cae5ed97a4","name":"Happy Addons for Elementor <= 3.20.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_elementor_data' Meta Field","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3207-authenticated-contributor-stored-cross-site-scripting-via-elementor-data-meta-field","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_data' meta field in all versions up to, and including, 3.20.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-02-02"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"efe64437c4362d7879375531ce9fb3c9e697ca5d635e0d671d9feac48fde609a","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.21.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.21.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-25468","name":"CVE-2026-25468","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-25468","description":"[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elementor allows Retrieve Embedded Sensitive Data.\n\nThis issue affects Happy Addons for Elementor: from n\/a through 3.20.8.","date":"2026-05-07"},{"id":"91dc97734b7e4116f8f3c147dca492aac7f3a224","name":"Happy Addons for Elementor <= 3.20.8 - Unauthenticated Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/happy-elementor-addons\/happy-addons-for-elementor-3208-unauthenticated-information-exposure","description":"The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.20.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2026-05-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-497","name":"Exposure of Sensitive System Information to an Unauthorized Control Sphere","description":"The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d1eab1ad6bee1bf451f5fc604c4142a854964ce0308287aef790100f67b99540","name":"HappyAddons for Elementor \u2013 160 Elementor Widgets, GSAP Animations &amp; Templates [happy-elementor-addons] < 3.50.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.50.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-85006","name":"CVE-2026-85006","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-85006","description":"[en] The HappyAddons for Elementor  WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject event-handler attributes that execute JavaScript in the browser of anyone who views the page, including higher-privileged users reviewing the content, even though such users do not hold the unfiltered_html capability.","date":"2026-09-23"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}}]},"updated":"1790228423"}