+ 37 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-47357
|
Happy Addons for Elementor [happy-elementor-addons] < 3.12.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 3.12.1
|
3.12.1 |
2024-09-30 |
✓ corregido en la última versión
|
|
CVE-2024-8801
|
Happy Addons for Elementor [happy-elementor-addons] < 3.12.3 |
Exposición de información sensible a un actor no autorizado |
Media
4,3
|
< 3.12.3
|
3.12.3 |
2024-09-23 |
✓ corregido en la última versión
|
|
CVE-2024-6627
|
Happy Addons for Elementor [happy-elementor-addons] < 3.11.3 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.11.3
|
3.11.3 |
2024-07-26 |
✓ corregido en la última versión
|
|
CVE-2024-5790
|
Happy Addons for Elementor [happy-elementor-addons] < 3.11.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.11.2
|
3.11.2 |
2024-06-28 |
✓ corregido en la última versión
|
|
CVE-2024-5041
|
Happy Addons for Elementor [happy-elementor-addons] < 3.11.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.11.0
|
3.11.0 |
2024-05-30 |
✓ corregido en la última versión
|
|
CVE-2024-5347
|
Happy Addons for Elementor [happy-elementor-addons] < 3.11.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.11.0
|
3.11.0 |
2024-05-30 |
✓ corregido en la última versión
|
|
CVE-2024-4865
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.9 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.9
|
3.10.9 |
2024-05-17 |
✓ corregido en la última versión
|
|
CVE-2024-5088
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.9 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.9
|
3.10.9 |
2024-05-17 |
✓ corregido en la última versión
|
|
CVE-2024-4478
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.8 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.8
|
3.10.8 |
2024-05-15 |
✓ corregido en la última versión
|
|
CVE-2024-4391
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.8 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.8
|
3.10.8 |
2024-05-15 |
✓ corregido en la última versión
|
|
CVE-2024-3890
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.7 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.7
|
3.10.7 |
2024-04-25 |
✓ corregido en la última versión
|
|
CVE-2024-3724
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.5 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.5
|
3.10.5 |
2024-04-19 |
✓ corregido en la última versión
|
|
CVE-2024-3891
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.6 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.6
|
3.10.6 |
2024-04-19 |
✓ corregido en la última versión
|
|
CVE-2024-32698
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.5 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 3.10.5
|
3.10.5 |
2024-04-19 |
✓ corregido en la última versión
|
|
CVE-2024-1387
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.5 |
Falta de control de autorización |
Media
4,3
|
< 3.10.5
|
3.10.5 |
2024-04-04 |
✓ corregido en la última versión
|
|
CVE-2024-2789
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.5 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.5
|
3.10.5 |
2024-04-04 |
✓ corregido en la última versión
|
|
CVE-2024-2786
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.4
|
3.10.4 |
2024-04-04 |
✓ corregido en la última versión
|
|
CVE-2024-2788
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.5 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.5
|
3.10.5 |
2024-04-04 |
✓ corregido en la última versión
|
|
CVE-2024-1498
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.4
|
3.10.4 |
2024-04-04 |
✓ corregido en la última versión
|
|
CVE-2024-2787
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.5 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.5
|
3.10.5 |
2024-04-04 |
✓ corregido en la última versión
|
|
CVE-2024-29108
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 3.10.2
|
3.10.2 |
2024-03-19 |
✓ corregido en la última versión
|
|
CVE-2024-1377
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.4
|
3.10.4 |
2024-03-06 |
✓ corregido en la última versión
|
|
CVE-2024-1366
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.4
|
3.10.4 |
2024-03-06 |
✓ corregido en la última versión
|
|
CVE-2024-0438
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.2
|
3.10.2 |
2024-02-13 |
✓ corregido en la última versión
|
|
CVE-2024-0838
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 3.10.2
|
3.10.2 |
2024-02-13 |
✓ corregido en la última versión
|
|
CVE-2024-24833
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.2 |
Falta de control de autorización |
Media
4,3
|
< 3.10.2
|
3.10.2 |
2024-02-02 |
✓ corregido en la última versión
|
|
—
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.1 |
— |
Desconocido
|
< 3.10.1
|
3.10.1 |
2024-01-09 |
✓ corregido en la última versión
|
|
CVE-2023-6632
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 3.10.0
|
3.10.0 |
2024-01-05 |
✓ corregido en la última versión
|
|
CVE-2023-51676
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.0 |
Falsificación de petición del lado del servidor (SSRF) |
Media
4,9
|
< 3.10.0
|
3.10.0 |
2023-12-27 |
✓ corregido en la última versión
|
|
CVE-2023-28989
|
Happy Addons for Elementor [happy-elementor-addons] < 3.8.3 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 3.8.3
|
3.8.3 |
2023-03-29 |
✓ corregido en la última versión
|
|
CVE-2022-47150
|
Happy Addons for Elementor [happy-elementor-addons] < 3.8.0 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 3.8.0
|
3.8.0 |
2023-03-21 |
✓ corregido en la última versión
|
|
CVE-2021-24292
|
Happy Addons for Elementor [happy-elementor-addons] < 2.24.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2.24.0
|
2.24.0 |
2021-04-26 |
✓ corregido en la última versión
|
|
—
|
Happy Addons for Elementor [happy-elementor-addons] < 3.12.3 |
— |
Media
6,4
|
< 3.12.3
|
3.12.3 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-2917
|
Happy Addons for Elementor [happy-elementor-addons] < 3.21.1 |
— |
Desconocido
|
< 3.21.1
|
3.21.1 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-2918
|
Happy Addons for Elementor [happy-elementor-addons] < 3.21.1 |
— |
Desconocido
|
< 3.21.1
|
3.21.1 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-1210
|
Happy Addons for Elementor [happy-elementor-addons] < 3.20.8 |
— |
Desconocido
|
< 3.20.8
|
3.20.8 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Happy Addons for Elementor [happy-elementor-addons] < 3.10.1 |
— |
Desconocido
|
< 3.10.1
|
3.10.1 |
— |
✓ corregido en la última versión
|
CVE-2024-47357
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-8801
The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including private, draft, and pending Elementor templates.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-6627
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-5790
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in all versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-5041
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-5347
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-4865
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-5088
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-4478
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied 'tooltip_position' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-4391
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-3890
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-3724
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Stack Group, Photo Stack, & Horizontal Timeline widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-3891
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-32698
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-1387
The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization on the duplicate_thing() function in all versions up to, and including, 3.10.4. This makes it possible for attackers, with contributor-level access and above, to clone arbitrary posts (including private and password protected ones) which may lead to information exposure.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-2789
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-2786
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on the title_tag attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-2788
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32698 is likely a duplicate of this issue.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-1498
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-2787
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-29108
Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.2).
Abu Hurayra discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.10.2.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-1377
Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.4).
Nikolas discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.10.4.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-1366
Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.4).
wesley (wcraft) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.10.4.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-0438
Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.2).
wesley (wcraft) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.10.2.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-0838
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-29108 is likely a duplicate of this issue.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-24833
Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.2).
Abu Hurayra discovered and reported this Broken Access Control vulnerability in WordPress Happy Addons for Elementor Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.10.2.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Happy Addons for Elementor [happy-elementor-addons] < 3.10.1
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AGe Gate Widget in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on the user supplied header URL value. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-6632
Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.0).
xEHLE discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.10.0.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-51676
Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.0).
Yuchen Ji discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system. This vulnerability has been fixed in version 3.10.0.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-28989
Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.8.3).
Muhammad Daffa discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.8.3.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2022-47150
Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.8.0).
Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.8.0.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2021-24292
The plugins have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_tag” parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a ‘save_builder’ request with the “heading_tag” set to “script”, and the actual “title” parameter set to JavaScript to be executed within the script tags added by the “heading_tag” parameter.
This JavaScript will then be executed when the saved page is viewed or previewed.
The other widgets that appear to be exploitable in this manner are:
fun-factor: "title_tag" script tag + Javascript in "fun_factor_title" parameter
gradient-heading: "title_tag" script tag + Javascript in "title" parameter
icon-box: "title_tag" script tag + Javascript in "title" parameter
infobox: "title_tag" script tag + Javascript in "title" parameter
member: "title_tag" script tag + Javascript in "title" parameter
post-list: "title_tag" script tag + Javascript in "title" parameter
review: "title_tag" script tag + Javascript in "title" parameter
step-flow: "title_tag" script tag + Javascript in "title" parameter
These vulnerabilities are nearly identical to the vulnerabilities we have recently disclosed in the main Elementor plugin: https://www.wordfence.com/blog/2021/03/cross-site-scripting-vulnerabilities-in-elementor-impact-over-7-million-sites/
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Happy Addons for Elementor [happy-elementor-addons] < 3.12.3
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-2917
The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate_thing` admin action handler. This is due to the `can_clone()` method only checking `current_user_can('edit_posts')` (a general capability) without performing object-level authorization such as `current_user_can('edit_post', $post_id)`, and the nonce being tied to the generic action name `ha_duplicate_thing` rather than to a specific post ID. This makes it possible for authenticated attackers, with Contributor-level access and above, to clone any published post, page, or custom post type by obtaining a valid clone nonce from their own posts and changing the `post_id` parameter to target other users' content. The clone operation copies the full post content, all post metadata (including potentially sensitive widget configurations and API tokens), and taxonomies into a new draft owned by the attacker.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-2918
The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_condition_update` AJAX action. This is due to the `validate_reqeust()` method using `current_user_can('edit_posts', $template_id)` instead of `current_user_can('edit_post', $template_id)` — failing to perform object-level authorization. Additionally, the `ha_get_current_condition` AJAX action lacks a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify the display conditions of any published `ha_library` template. Because the `cond_to_html()` renderer outputs condition values into HTML attributes without proper escaping (using string concatenation instead of `esc_attr()`), an attacker can inject event handler attributes (e.g., `onmouseover`) that execute JavaScript when an administrator views the Template Conditions panel, resulting in Stored Cross-Site Scripting.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-1210
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_data' meta field in all versions up to, and including, 3.20.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Happy Addons for Elementor [happy-elementor-addons] < 3.10.1
The plugin is vulnerable to Stored Cross-Site Scripting via the plugin's AGe Gate Widget in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on the user supplied header URL value. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Mantén Happy Elementor Addons actualizado — 3.22.0 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.