CVE · High

CVE-2023-41236 — Happy Addons for Elementor Pro [happy-elementor-addons-pro] < 2.8.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-41236 Happy Addons for Elementor Pro [happy-elementor-addons-pro] < 2.8.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 2.8.1 2.8.1 2023-08-29

CVE-2023-41236

The Happy Addons for Elementor Pro plugin versions below 2.8.1 contain a cross-site scripting vulnerability that enables attackers to inject malicious scripts into websites, potentially leading to unwanted redirects, advertisements, and arbitrary HTML execution when users visit affected pages. The vulnerability was discovered and reported by Rafie Muhammad but remains unfixed as the vendor has not released a patched version or responded to the disclosure. Website administrators using this plugin should be aware that no official fix is currently available.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.