WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Happy Elementor Addons?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Happy Elementor Addons — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: happy-elementor-addons
  • 400000+ instalaciones activas

elementorelementor addonselementor widgetheader footer buildermega menu

Estado de mantenimiento

  • Última versión conocida: 3.22.0
  • Requiere PHP: 7.4+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

42 CVEs conocidos registrados para Happy Elementor Addons.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-25468 Happy Addons for Elementor [happy-elementor-addons] < 3.21.0 Exposición de información sensible del sistema a una esfera de control no autorizada Media 5,3 < 3.21.0 3.21.0 2026-05-07 ✓ corregido en la última versión
CVE-2025-68999 Happy Addons for Elementor [happy-elementor-addons] < 3.20.6 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 8,5 < 3.20.6 3.20.6 2026-01-22 ✓ corregido en la última versión
CVE-2025-14635 Happy Addons for Elementor [happy-elementor-addons] < 3.20.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 3.20.4 3.20.4 2025-12-22 ✓ corregido en la última versión
CVE-2025-63077 Happy Addons for Elementor [happy-elementor-addons] < 3.20.4 Falta de control de autorización Media 4,3 < 3.20.4 3.20.4 2025-12-04 ✓ corregido en la última versión
CVE-2025-30766 Happy Addons for Elementor [happy-elementor-addons] < 3.16.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 3.16.3 3.16.3 2025-03-27 ✓ corregido en la última versión
CVE-2024-12852 Happy Addons for Elementor [happy-elementor-addons] < 3.15.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 3.15.2 3.15.2 2025-01-07 ✓ corregido en la última versión
CVE-2024-10538 Happy Addons for Elementor [happy-elementor-addons] < 3.12.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 3.12.6 3.12.6 2024-11-11 ✓ corregido en la última versión
CVE-2024-48045 Happy Addons for Elementor [happy-elementor-addons] < 3.12.4 Falta de control de autorización Media 4,3 < 3.12.4 3.12.4 2024-10-13 ✓ corregido en la última versión

CVE-2026-25468

The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.20.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-68999

The Happy Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.20.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-14635

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom_js' parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, despite the intended role restriction of Custom JS to Administrators.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-63077

The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.20.3. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-30766

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.16.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-12852

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-10538

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.12.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-48045

The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_reqeust() function in versions up to, and including, 3.12.3. This makes it possible for authenticated attackers, with contributor-level access and above, to view draft/private/password protected templates.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 37 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-47357 Happy Addons for Elementor [happy-elementor-addons] < 3.12.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 3.12.1 3.12.1 2024-09-30 ✓ corregido en la última versión
CVE-2024-8801 Happy Addons for Elementor [happy-elementor-addons] < 3.12.3 Exposición de información sensible a un actor no autorizado Media 4,3 < 3.12.3 3.12.3 2024-09-23 ✓ corregido en la última versión
CVE-2024-6627 Happy Addons for Elementor [happy-elementor-addons] < 3.11.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.11.3 3.11.3 2024-07-26 ✓ corregido en la última versión
CVE-2024-5790 Happy Addons for Elementor [happy-elementor-addons] < 3.11.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.11.2 3.11.2 2024-06-28 ✓ corregido en la última versión
CVE-2024-5041 Happy Addons for Elementor [happy-elementor-addons] < 3.11.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.11.0 3.11.0 2024-05-30 ✓ corregido en la última versión
CVE-2024-5347 Happy Addons for Elementor [happy-elementor-addons] < 3.11.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.11.0 3.11.0 2024-05-30 ✓ corregido en la última versión
CVE-2024-4865 Happy Addons for Elementor [happy-elementor-addons] < 3.10.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.9 3.10.9 2024-05-17 ✓ corregido en la última versión
CVE-2024-5088 Happy Addons for Elementor [happy-elementor-addons] < 3.10.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.9 3.10.9 2024-05-17 ✓ corregido en la última versión
CVE-2024-4478 Happy Addons for Elementor [happy-elementor-addons] < 3.10.8 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.8 3.10.8 2024-05-15 ✓ corregido en la última versión
CVE-2024-4391 Happy Addons for Elementor [happy-elementor-addons] < 3.10.8 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.8 3.10.8 2024-05-15 ✓ corregido en la última versión
CVE-2024-3890 Happy Addons for Elementor [happy-elementor-addons] < 3.10.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.7 3.10.7 2024-04-25 ✓ corregido en la última versión
CVE-2024-3724 Happy Addons for Elementor [happy-elementor-addons] < 3.10.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.5 3.10.5 2024-04-19 ✓ corregido en la última versión
CVE-2024-3891 Happy Addons for Elementor [happy-elementor-addons] < 3.10.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.6 3.10.6 2024-04-19 ✓ corregido en la última versión
CVE-2024-32698 Happy Addons for Elementor [happy-elementor-addons] < 3.10.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 3.10.5 3.10.5 2024-04-19 ✓ corregido en la última versión
CVE-2024-1387 Happy Addons for Elementor [happy-elementor-addons] < 3.10.5 Falta de control de autorización Media 4,3 < 3.10.5 3.10.5 2024-04-04 ✓ corregido en la última versión
CVE-2024-2789 Happy Addons for Elementor [happy-elementor-addons] < 3.10.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.5 3.10.5 2024-04-04 ✓ corregido en la última versión
CVE-2024-2786 Happy Addons for Elementor [happy-elementor-addons] < 3.10.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.4 3.10.4 2024-04-04 ✓ corregido en la última versión
CVE-2024-2788 Happy Addons for Elementor [happy-elementor-addons] < 3.10.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.5 3.10.5 2024-04-04 ✓ corregido en la última versión
CVE-2024-1498 Happy Addons for Elementor [happy-elementor-addons] < 3.10.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.4 3.10.4 2024-04-04 ✓ corregido en la última versión
CVE-2024-2787 Happy Addons for Elementor [happy-elementor-addons] < 3.10.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.5 3.10.5 2024-04-04 ✓ corregido en la última versión
CVE-2024-29108 Happy Addons for Elementor [happy-elementor-addons] < 3.10.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 3.10.2 3.10.2 2024-03-19 ✓ corregido en la última versión
CVE-2024-1377 Happy Addons for Elementor [happy-elementor-addons] < 3.10.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.4 3.10.4 2024-03-06 ✓ corregido en la última versión
CVE-2024-1366 Happy Addons for Elementor [happy-elementor-addons] < 3.10.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.4 3.10.4 2024-03-06 ✓ corregido en la última versión
CVE-2024-0438 Happy Addons for Elementor [happy-elementor-addons] < 3.10.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.2 3.10.2 2024-02-13 ✓ corregido en la última versión
CVE-2024-0838 Happy Addons for Elementor [happy-elementor-addons] < 3.10.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.10.2 3.10.2 2024-02-13 ✓ corregido en la última versión
CVE-2024-24833 Happy Addons for Elementor [happy-elementor-addons] < 3.10.2 Falta de control de autorización Media 4,3 < 3.10.2 3.10.2 2024-02-02 ✓ corregido en la última versión
Happy Addons for Elementor [happy-elementor-addons] < 3.10.1 Desconocido < 3.10.1 3.10.1 2024-01-09 ✓ corregido en la última versión
CVE-2023-6632 Happy Addons for Elementor [happy-elementor-addons] < 3.10.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.10.0 3.10.0 2024-01-05 ✓ corregido en la última versión
CVE-2023-51676 Happy Addons for Elementor [happy-elementor-addons] < 3.10.0 Falsificación de petición del lado del servidor (SSRF) Media 4,9 < 3.10.0 3.10.0 2023-12-27 ✓ corregido en la última versión
CVE-2023-28989 Happy Addons for Elementor [happy-elementor-addons] < 3.8.3 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 3.8.3 3.8.3 2023-03-29 ✓ corregido en la última versión
CVE-2022-47150 Happy Addons for Elementor [happy-elementor-addons] < 3.8.0 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 3.8.0 3.8.0 2023-03-21 ✓ corregido en la última versión
CVE-2021-24292 Happy Addons for Elementor [happy-elementor-addons] < 2.24.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 2.24.0 2.24.0 2021-04-26 ✓ corregido en la última versión
Happy Addons for Elementor [happy-elementor-addons] < 3.12.3 Media 6,4 < 3.12.3 3.12.3 0000-00-00 ✓ corregido en la última versión
CVE-2026-2917 Happy Addons for Elementor [happy-elementor-addons] < 3.21.1 Desconocido < 3.21.1 3.21.1 0000-00-00 ✓ corregido en la última versión
CVE-2026-2918 Happy Addons for Elementor [happy-elementor-addons] < 3.21.1 Desconocido < 3.21.1 3.21.1 0000-00-00 ✓ corregido en la última versión
CVE-2026-1210 Happy Addons for Elementor [happy-elementor-addons] < 3.20.8 Desconocido < 3.20.8 3.20.8 0000-00-00 ✓ corregido en la última versión
Happy Addons for Elementor [happy-elementor-addons] < 3.10.1 Desconocido < 3.10.1 3.10.1 ✓ corregido en la última versión

CVE-2024-47357

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-8801

The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including private, draft, and pending Elementor templates.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-6627

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-5790

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in all versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-5041

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-5347

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4865

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-5088

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4478

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied 'tooltip_position' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4391

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-3890

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-3724

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Stack Group, Photo Stack, & Horizontal Timeline widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-3891

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-32698

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-1387

The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization on the duplicate_thing() function in all versions up to, and including, 3.10.4. This makes it possible for attackers, with contributor-level access and above, to clone arbitrary posts (including private and password protected ones) which may lead to information exposure.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-2789

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-2786

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on the title_tag attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-2788

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32698 is likely a duplicate of this issue.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-1498

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-2787

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-29108

Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.2). Abu Hurayra discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.10.2. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1377

Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.4). Nikolas discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.10.4. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1366

Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.4). wesley (wcraft) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.10.4. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-0438

Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.2). wesley (wcraft) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.10.2. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-0838

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-29108 is likely a duplicate of this issue.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-24833

Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.2). Abu Hurayra discovered and reported this Broken Access Control vulnerability in WordPress Happy Addons for Elementor Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.10.2. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Happy Addons for Elementor [happy-elementor-addons] < 3.10.1

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AGe Gate Widget in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on the user supplied header URL value. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-6632

Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.0). xEHLE discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.10.0. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-51676

Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.10.0). Yuchen Ji discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system. This vulnerability has been fixed in version 3.10.0. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-28989

Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.8.3). Muhammad Daffa discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.8.3.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-47150

Update the WordPress Happy Addons for Elementor plugin to the latest available version (at least 3.8.0). Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Happy Addons for Elementor Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.8.0.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-24292

The plugins have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_tag” parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a ‘save_builder’ request with the “heading_tag” set to “script”, and the actual “title” parameter set to JavaScript to be executed within the script tags added by the “heading_tag” parameter. This JavaScript will then be executed when the saved page is viewed or previewed. The other widgets that appear to be exploitable in this manner are: fun-factor: "title_tag" script tag + Javascript in "fun_factor_title" parameter gradient-heading: "title_tag" script tag + Javascript in "title" parameter icon-box: "title_tag" script tag + Javascript in "title" parameter infobox: "title_tag" script tag + Javascript in "title" parameter member: "title_tag" script tag + Javascript in "title" parameter post-list: "title_tag" script tag + Javascript in "title" parameter review: "title_tag" script tag + Javascript in "title" parameter step-flow: "title_tag" script tag + Javascript in "title" parameter These vulnerabilities are nearly identical to the vulnerabilities we have recently disclosed in the main Elementor plugin: https://www.wordfence.com/blog/2021/03/cross-site-scripting-vulnerabilities-in-elementor-impact-over-7-million-sites/

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Happy Addons for Elementor [happy-elementor-addons] < 3.12.3

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-2917

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate_thing` admin action handler. This is due to the `can_clone()` method only checking `current_user_can('edit_posts')` (a general capability) without performing object-level authorization such as `current_user_can('edit_post', $post_id)`, and the nonce being tied to the generic action name `ha_duplicate_thing` rather than to a specific post ID. This makes it possible for authenticated attackers, with Contributor-level access and above, to clone any published post, page, or custom post type by obtaining a valid clone nonce from their own posts and changing the `post_id` parameter to target other users' content. The clone operation copies the full post content, all post metadata (including potentially sensitive widget configurations and API tokens), and taxonomies into a new draft owned by the attacker.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-2918

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_condition_update` AJAX action. This is due to the `validate_reqeust()` method using `current_user_can('edit_posts', $template_id)` instead of `current_user_can('edit_post', $template_id)` — failing to perform object-level authorization. Additionally, the `ha_get_current_condition` AJAX action lacks a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify the display conditions of any published `ha_library` template. Because the `cond_to_html()` renderer outputs condition values into HTML attributes without proper escaping (using string concatenation instead of `esc_attr()`), an attacker can inject event handler attributes (e.g., `onmouseover`) that execute JavaScript when an administrator views the Template Conditions panel, resulting in Stored Cross-Site Scripting.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-1210

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_data' meta field in all versions up to, and including, 3.20.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Happy Addons for Elementor [happy-elementor-addons] < 3.10.1

The plugin is vulnerable to Stored Cross-Site Scripting via the plugin's AGe Gate Widget in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on the user supplied header URL value. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Happy Elementor Addons actualizado — 3.22.0 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.