Extension WordPress
Vulnérabilités Happy Addons for Elementor, page 2
Cette page rassemble les failles publiées pour Happy Addons for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Happy Addons for Elementor
44 fiches
Happy Addons for Elementor Authenticated (Contributor+) Stored-XSS <= 3.10.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar Widget
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user…
*-3.10.7
3.10.8
15/05/2024
Happy Addons for Elementor <= 3.10.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group Widget
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user…
*-3.10.7
3.10.8
15/05/2024
Happy Addons for Elementor <= 3.10.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Calendly Widget
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-3.10.6
3.10.7
25/04/2024
Happy Addons for Elementor <= 3.10.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-3.10.4
3.10.5
19/04/2024
Happy Addons for Elementor <= 3.10.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied…
*-3.10.5
3.10.6
19/04/2024
Happy Addons for Elementor <= 3.10.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group, Photo Stack, & Horizontal Timeline
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Stack Group, Photo Stack, & Horizontal Timeline widgets in all versions up to, and including, 3.10.4 due to insufficient input…
*-3.10.4
3.10.5
19/04/2024
Happy Addons for Elementor <= 3.10.4 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via title_tag
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on the title_tag attribute. This…
*-3.10.4
3.10.5
04/04/2024
Happy Addons for Elementor <= 3.10.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title HTML Tag
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user…
*-3.10.4
3.10.5
04/04/2024
Happy Addons for Elementor <= 3.10.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Stack Widget
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping on user…
*-3.10.3
3.10.4
04/04/2024
Happy Addons for Elementor <= 3.10.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title HTML Tag
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user…
*-3.10.4
3.10.5
04/04/2024
Happy Addons for Elementor <= 3.10.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Calendy
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied…
*-3.10.4
3.10.5
04/04/2024
Happy Addons for Elementor <= 3.10.4 – Incorrect Authorization to Information Exposure
The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization on the duplicate_thing() function in all versions up to, and including, 3.10.4. This makes it possible for attackers, with…
*-3.10.4
3.10.5
04/04/2024
Happy Addons for Elementor <= 3.10.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Author Meta Widget
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output…
*-3.10.3
3.10.4
06/03/2024
Happy Addons for Elementor <= 3.10.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Archive Title Widget
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_tag’ attribute of the Archive Title widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output…
*-3.10.3
3.10.4
06/03/2024
Happy Addons for Elementor <= 3.10.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output…
*-3.10.1
3.10.2
13/02/2024
Happy Addons for Elementor <= 3.10.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and…
*-3.10.1
3.10.2
13/02/2024
Happy Addons for Elementor <= 3.10.1 – Missing Authorization via add_row_actions
The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the add_row_actions() function in versions up to, and including, 3.10.1. This makes it possible for authenticated…
*-3.10.1
3.10.2
02/02/2024
Happy Elementor Addons <= 3.10.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AGe Gate Widget in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on the…
*-3.10.0
3.10.1
09/01/2024
Happy Addons for Elementor <= 3.9.1.1 – Reflected Cross-Site Scripting
The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input…
*-3.9.1.1
3.10.0
05/01/2024
Happy Addons for Elementor <= 3.9.1.1 – Server Side Request Forgery
The Happy Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.10.0 (exclusive). This makes it possible for authenticated attackers, with contributor access and above, to make web requests to…
[*, 3.10.0)
3.10.0
27/12/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.