HappyAddons for Elementor – 160 Elementor Widgets, GSAP Animations & Templates <= 3.50.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Bar Page Settings

Medium 6.4 CWE-79Fixed in 3.50.1
ID
WPSEC-2026-0435
Plugin
HappyAddons for Elementor – 160 Elementor Widgets, GSAP Animations & Templates (happy-elementor-addons)
Affected
from 3.14.0 before 3.50.1
Remediation
Update to 3.50.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin High · Affected versions High among sites WPSec scans, 2026-10-06
Attack surface
HappyAddons for Elementor – 160 Elementor Widgets, GSAP Animations & Templates on WPSec AttackSurface
Fix released
Published

Description

The HappyAddons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Reading Progress Bar page settings (ha_rpb_single_enable and ha_rpb_single_disable) in versions 3.14.0 up to, and including, 3.50.0 due to insufficient input sanitization and output escaping when these values are echoed into an inline JavaScript block in the Elementor editor preview. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts that execute when a user who can edit the page opens it in the Elementor editor.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0