HappyAddons for Elementor – 160 Elementor Widgets, GSAP Animations & Templates <= 3.50.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Bar Page Settings
- ID
- WPSEC-2026-0435
- Plugin
- HappyAddons for Elementor – 160 Elementor Widgets, GSAP Animations & Templates (happy-elementor-addons)
- Affected
- from 3.14.0 before 3.50.1
- Remediation
- Update to 3.50.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin High · Affected versions High among sites WPSec scans, 2026-10-06
- Attack surface
- HappyAddons for Elementor – 160 Elementor Widgets, GSAP Animations & Templates on WPSec AttackSurface
- Fix released
- Published
Description
The HappyAddons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Reading Progress Bar page settings (ha_rpb_single_enable and ha_rpb_single_disable) in versions 3.14.0 up to, and including, 3.50.0 due to insufficient input sanitization and output escaping when these values are echoed into an inline JavaScript block in the Elementor editor preview. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts that execute when a user who can edit the page opens it in the Elementor editor.
References
- https://wpsec.com/vuln/WPSEC-2026-0435/
- https://plugins.svn.wordpress.org/happy-elementor-addons/tags/3.50.1/
- https://wordpress.org/plugins/happy-elementor-addons/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS