CVE-2021-24292
Happy Addons for Elementor before version 2.24.0 contains multiple stored cross-site scripting vulnerabilities affecting nine widgets including Card, Fun Factor, Gradient Heading, Icon Box, Infobox, Member, Post List, Review, and Step Flow. Contributors and other lower-privileged users can exploit these flaws by manipulating the title_tag parameter to accept script tags and injecting malicious JavaScript into title-related fields, which executes when the page is subsequently viewed or previewed. The vulnerability stems from insufficient validation of the title_tag parameter despite frontend restrictions on acceptable HTML tags.
Based on public CVE data (MITRE/NVD).