Extension WordPress

Vulnérabilités Happy Addons for Elementor

Cette page rassemble les failles publiées pour Happy Addons for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

44Vulnérabilités
0Critiques
44Avec correctif
6,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Happy Addons for Elementor

44 fiches

CVE-2026-2917 Moyenne · 5,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.21.0 – Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate_thing` admin action handler. This is due to the `can_clone()` method only checking…

Versions affectées

*-3.21.0

Correctif

3.21.1

Publication

10/03/2026

CVE-2026-2918 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.21.0 – Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_condition_update` AJAX action. This is due to the `validate_reqeust()` method using `current_user_can('edit_posts', $template_id)`…

Versions affectées

*-3.21.0

Correctif

3.21.1

Publication

10/03/2026

CVE-2026-1210 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.20.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via '_elementor_data' Meta Field

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_data' meta field in all versions up to, and including, 3.20.7 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-3.20.7

Correctif

3.20.8

Publication

02/02/2026

CVE-2025-14635 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.20.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom_js' parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-3.20.3

Correctif

3.20.4

Publication

22/12/2025

CVE-2024-5647 Moyenne · 6,4
Happy Addons for Elementor

Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

Versions affectées

*-3.12.2

Correctif

3.12.3

Publication

02/07/2025

CVE-2025-30766 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.16.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.16.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-3.16.2

Correctif

3.16.3

Publication

27/03/2025

CVE-2024-12852 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.15.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output…

Versions affectées

*-3.15.1

Correctif

3.15.2

Publication

07/01/2025

CVE-2024-10538 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.12.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.12.5 due to insufficient input sanitization and output…

Versions affectées

*-3.12.5

Correctif

3.12.6

Publication

11/11/2024

CVE-2024-47357 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.12.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-3.12.0

Correctif

3.12.1

Publication

30/09/2024

CVE-2024-8801 Moyenne · 4,3
Happy Addons for Elementor

Happy Addons for Elementor <= 3.12.2 – Authenticated (Contributor+) Sensitive Information Exposure

The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level access and…

Versions affectées

*-3.12.2

Correctif

3.12.3

Publication

23/09/2024

CVE-2024-6627 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.11.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via PDF View Widget

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-3.11.2

Correctif

3.11.3

Publication

27/07/2024

CVE-2024-5790 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.11.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Gradient Heading Widget

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in all versions up to, and including, 3.11.1 due to insufficient input sanitization and…

Versions affectées

*-3.11.1

Correctif

3.11.2

Publication

28/06/2024

CVE-2024-5347 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation Widget

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in all versions up to, and including, 3.10.9 due to insufficient input sanitization and…

Versions affectées

*-3.10.9

Correctif

3.11.0

Publication

30/05/2024

CVE-2024-5041 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-3.10.9

Correctif

3.11.0

Publication

30/05/2024

CVE-2024-4865 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via _id Parameter

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-3.10.8

Correctif

3.10.9

Publication

17/05/2024

CVE-2024-5088 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-3.10.8

Correctif

3.10.9

Publication

17/05/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités