CVE · Medium

CVE-2021-24292 — Happy Addons for Elementor [happy-elementor-addons] < 2.24.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24292 Happy Addons for Elementor [happy-elementor-addons] < 2.24.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.24.0 2.24.0 2021-04-26

CVE-2021-24292

Happy Addons for Elementor before version 2.24.0 contains multiple stored cross-site scripting vulnerabilities affecting nine widgets including Card, Fun Factor, Gradient Heading, Icon Box, Infobox, Member, Post List, Review, and Step Flow. Contributors and other lower-privileged users can exploit these flaws by manipulating the title_tag parameter to accept script tags and injecting malicious JavaScript into title-related fields, which executes when the page is subsequently viewed or previewed. The vulnerability stems from insufficient validation of the title_tag parameter despite frontend restrictions on acceptable HTML tags.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.