CVE-2023-41236
The Happy Addons for Elementor Pro plugin versions below 2.8.1 contain a cross-site scripting vulnerability that enables attackers to inject malicious scripts into websites, potentially leading to unwanted redirects, advertisements, and arbitrary HTML execution when users visit affected pages. The vulnerability was discovered and reported by Rafie Muhammad but remains unfixed as the vendor has not released a patched version or responded to the disclosure. Website administrators using this plugin should be aware that no official fix is currently available.
Based on public CVE data (MITRE/NVD).