CVE · High

CVE-2025-68999 — Happy Addons for Elementor [happy-elementor-addons] < 3.20.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-68999 Happy Addons for Elementor [happy-elementor-addons] < 3.20.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.5 < 3.20.6 3.20.6 2026-01-22

CVE-2025-68999

The Happy Addons for Elementor plugin has a SQL Injection vulnerability in versions 3.20.4 and earlier, caused by inadequate escaping of user inputs and insufficient query preparation. Authenticated attackers with at least contributor-level access can exploit this to append malicious SQL queries that may reveal sensitive data from the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.