CVE · Medium

CVE-2024-1387 — Happy Addons for Elementor [happy-elementor-addons] < 3.10.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1387 Happy Addons for Elementor [happy-elementor-addons] < 3.10.5 Missing Authorization Medium 4.3 < 3.10.5 3.10.5 2024-04-04

CVE-2024-1387

The Happy Addons for Elementor plugin contains an authorization flaw in its duplicate_thing() function affecting versions 3.10.4 and earlier, allowing users with contributor privileges or higher to duplicate any post without proper permission checks. This vulnerability enables attackers to clone private and password-protected posts, potentially exposing sensitive information. The issue was resolved in version 3.10.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.