Extension WordPress

Vulnérabilités Happy Addons for Elementor, page 2

Cette page rassemble les failles publiées pour Happy Addons for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

44Vulnérabilités
0Critiques
44Avec correctif
6,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Happy Addons for Elementor

44 fiches

CVE-2024-4391 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor Authenticated (Contributor+) Stored-XSS <= 3.10.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar Widget

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-3.10.7

Correctif

3.10.8

Publication

15/05/2024

CVE-2024-4478 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group Widget

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-3.10.7

Correctif

3.10.8

Publication

15/05/2024

CVE-2024-3890 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Calendly Widget

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes.…

Versions affectées

*-3.10.6

Correctif

3.10.7

Publication

25/04/2024

CVE-2024-32698 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.4 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-3.10.4

Correctif

3.10.5

Publication

19/04/2024

CVE-2024-3891 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied…

Versions affectées

*-3.10.5

Correctif

3.10.6

Publication

19/04/2024

CVE-2024-3724 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group, Photo Stack, & Horizontal Timeline

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Stack Group, Photo Stack, & Horizontal Timeline widgets in all versions up to, and including, 3.10.4 due to insufficient input…

Versions affectées

*-3.10.4

Correctif

3.10.5

Publication

19/04/2024

CVE-2024-2786 Moyenne · 5,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.4 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via title_tag

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on the title_tag attribute. This…

Versions affectées

*-3.10.4

Correctif

3.10.5

Publication

04/04/2024

CVE-2024-2788 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title HTML Tag

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-3.10.4

Correctif

3.10.5

Publication

04/04/2024

CVE-2024-1498 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Stack Widget

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-3.10.3

Correctif

3.10.4

Publication

04/04/2024

CVE-2024-2787 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title HTML Tag

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-3.10.4

Correctif

3.10.5

Publication

04/04/2024

CVE-2024-2789 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Calendy

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied…

Versions affectées

*-3.10.4

Correctif

3.10.5

Publication

04/04/2024

CVE-2024-1377 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Author Meta Widget

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output…

Versions affectées

*-3.10.3

Correctif

3.10.4

Publication

06/03/2024

CVE-2024-1366 Moyenne · 6,4
Happy Addons for Elementor

Happy Addons for Elementor <= 3.10.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Archive Title Widget

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_tag’ attribute of the Archive Title widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output…

Versions affectées

*-3.10.3

Correctif

3.10.4

Publication

06/03/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités