Happy Addons for Elementor

64 known CVEs 400K+ active installs

Scan My Site Free

UNKNOWN: 64
Known Vulnerabilities 64
CVE-2026-2918 UNKNOWN EPSS 0.1%
Published 2026-03-11 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_condition_update` AJAX action. This is du
CVE-2026-2917 UNKNOWN EPSS 0.1%
Published 2026-03-11 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate_thing` admin action handler. Th
CVE-2026-1210 UNKNOWN EPSS 0.2%
Published 2026-02-03 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_data' meta field in all versions up to, and including, 3.20.7 due to insufficient i
CVE-2025-14635 UNKNOWN EPSS 0.2%
Published 2025-12-23 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom_js' parameter in all versions up to, and including, 3.20.3 due to insufficient
CVE-2024-48045 UNKNOWN EPSS 0.3%
Published 2024-11-01 · Affected: *
Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy A
CVE-2024-48045 UNKNOWN EPSS 0.3%
Published 2024-11-01 · Affected: *
Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy A
CVE-2024-48045 UNKNOWN EPSS 0.3%
Published 2024-11-01 · Affected: *
Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy A
CVE-2024-48045 UNKNOWN EPSS 0.3%
Published 2024-11-01 · Affected: *
Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy A
CVE-2024-47357 UNKNOWN EPSS 0.2%
Published 2024-10-06 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Stored XSS.This issue affect
CVE-2024-47357 UNKNOWN EPSS 0.2%
Published 2024-10-06 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Stored XSS.This issue affect
CVE-2024-47357 UNKNOWN EPSS 0.2%
Published 2024-10-06 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Stored XSS.This issue affect
CVE-2024-47357 UNKNOWN EPSS 0.2%
Published 2024-10-06 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Stored XSS.This issue affect
CVE-2024-5790 UNKNOWN EPSS 0.3%
Published 2024-06-29 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in all versions up to, and includin
CVE-2024-5790 UNKNOWN EPSS 0.3%
Published 2024-06-29 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in all versions up to, and includin
CVE-2024-5347 UNKNOWN EPSS 0.3%
Published 2024-05-31 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in all versions up to, and includi
CVE-2024-5347 UNKNOWN EPSS 0.3%
Published 2024-05-31 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in all versions up to, and includi
CVE-2024-5041 UNKNOWN EPSS 0.2%
Published 2024-05-31 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, 3.10.9 due to insufficie
CVE-2024-5041 UNKNOWN EPSS 0.2%
Published 2024-05-31 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, 3.10.9 due to insufficie
CVE-2024-5088 UNKNOWN EPSS 0.3%
Published 2024-05-18 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitiza
CVE-2024-5088 UNKNOWN EPSS 0.3%
Published 2024-05-18 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitiza
CVE-2024-4865 UNKNOWN EPSS 0.3%
Published 2024-05-18 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitiza
CVE-2024-4865 UNKNOWN EPSS 0.3%
Published 2024-05-18 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitiza
CVE-2024-4391 UNKNOWN EPSS 0.2%
Published 2024-05-16 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient
CVE-2024-4391 UNKNOWN EPSS 0.2%
Published 2024-05-16 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient
CVE-2024-4478 UNKNOWN EPSS 0.3%
Published 2024-05-16 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input
CVE-2024-4478 UNKNOWN EPSS 0.3%
Published 2024-05-16 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input
CVE-2024-24833 UNKNOWN EPSS 0.3%
Published 2024-05-08 · Affected: *
Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for Elementor: from n/a through <= 3.10.1.
CVE-2024-24833 UNKNOWN EPSS 0.3%
Published 2024-05-08 · Affected: *
Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for Elementor: from n/a through <= 3.10.1.
CVE-2024-24833 UNKNOWN EPSS 0.3%
Published 2024-05-08 · Affected: *
Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for Elementor: from n/a through <= 3.10.1.
CVE-2024-24833 UNKNOWN EPSS 0.3%
Published 2024-05-08 · Affected: *
Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for Elementor: from n/a through <= 3.10.1.
CVE-2024-3891 UNKNOWN EPSS 0.4%
Published 2024-05-02 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitiz
CVE-2024-3891 UNKNOWN EPSS 0.4%
Published 2024-05-02 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitiz
CVE-2024-3724 UNKNOWN EPSS 0.4%
Published 2024-05-02 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Stack Group, Photo Stack, & Horizontal Timeline widgets in all versions up to, a
CVE-2024-3724 UNKNOWN EPSS 0.4%
Published 2024-05-02 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Stack Group, Photo Stack, & Horizontal Timeline widgets in all versions up to, a
CVE-2024-3890 UNKNOWN EPSS 0.3%
Published 2024-04-26 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitiza
CVE-2024-3890 UNKNOWN EPSS 0.3%
Published 2024-04-26 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget in all versions up to, and including, 3.10.5 due to insufficient input sanitiza
CVE-2024-32698 UNKNOWN EPSS 0.2%
Published 2024-04-22 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for
CVE-2024-32698 UNKNOWN EPSS 0.2%
Published 2024-04-22 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for
CVE-2024-32698 UNKNOWN EPSS 0.2%
Published 2024-04-22 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for
CVE-2024-32698 UNKNOWN EPSS 0.2%
Published 2024-04-22 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for
CVE-2024-2789 UNKNOWN EPSS 0.3%
Published 2024-04-09 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input
CVE-2024-2789 UNKNOWN EPSS 0.3%
Published 2024-04-09 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input
CVE-2024-2788 UNKNOWN EPSS 0.3%
Published 2024-04-09 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sani
CVE-2024-2788 UNKNOWN EPSS 0.3%
Published 2024-04-09 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sani
CVE-2024-2787 UNKNOWN EPSS 0.3%
Published 2024-04-09 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sani
CVE-2024-2787 UNKNOWN EPSS 0.3%
Published 2024-04-09 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sani
CVE-2024-2786 UNKNOWN EPSS 0.4%
Published 2024-04-09 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization
CVE-2024-2786 UNKNOWN EPSS 0.4%
Published 2024-04-09 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization
CVE-2024-1498 UNKNOWN EPSS 0.4%
Published 2024-04-09 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient in
CVE-2024-1498 UNKNOWN EPSS 0.4%
Published 2024-04-09 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient in
CVE-2024-1387 UNKNOWN EPSS 0.5%
Published 2024-04-09 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization on the duplicate_thing() function in all versions up to, and includin
CVE-2024-1387 UNKNOWN EPSS 0.5%
Published 2024-04-09 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization on the duplicate_thing() function in all versions up to, and includin
CVE-2024-1377 UNKNOWN EPSS 0.3%
Published 2024-03-07 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all versions up to, and including, 3.1
CVE-2024-1377 UNKNOWN EPSS 0.3%
Published 2024-03-07 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all versions up to, and including, 3.1
CVE-2024-1366 UNKNOWN EPSS 0.3%
Published 2024-03-07 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_tag’ attribute of the Archive Title widget in all versions up to, and including,
CVE-2024-1366 UNKNOWN EPSS 0.3%
Published 2024-03-07 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_tag’ attribute of the Archive Title widget in all versions up to, and including,
CVE-2024-0838 UNKNOWN EPSS 0.4%
Published 2024-02-29 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and including, 3.10.1 due to in
CVE-2024-0838 UNKNOWN EPSS 0.4%
Published 2024-02-29 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and including, 3.10.1 due to in
CVE-2024-0438 UNKNOWN EPSS 0.5%
Published 2024-02-29 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insu
CVE-2024-0438 UNKNOWN EPSS 0.5%
Published 2024-02-29 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wrapper link parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insu
CVE-2023-6632 UNKNOWN EPSS 0.4%
Published 2024-01-11 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elem
CVE-2023-6632 UNKNOWN EPSS 0.4%
Published 2024-01-11 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elem
CVE-2023-6632 UNKNOWN EPSS 0.4%
Published 2024-01-11 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elem
CVE-2023-6632 UNKNOWN EPSS 0.4%
Published 2024-01-11 · Affected: *
The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elem

Is Happy Addons for Elementor running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free