{
 "id": "WPSEC-2026-0435",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0435/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0435/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0435/index.md",
 "title": "HappyAddons for Elementor – 160 Elementor Widgets, GSAP Animations & Templates <= 3.50.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Bar Page Settings",
 "description": "The HappyAddons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Reading Progress Bar page settings (ha_rpb_single_enable and ha_rpb_single_disable) in versions 3.14.0 up to, and including, 3.50.0 due to insufficient input sanitization and output escaping when these values are echoed into an inline JavaScript block in the Elementor editor preview. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts that execute when a user who can edit the page opens it in the Elementor editor.",
 "plugin": {
  "slug": "happy-elementor-addons",
  "name": "HappyAddons for Elementor – 160 Elementor Widgets, GSAP Animations & Templates",
  "full_name": "HappyAddons for Elementor – 160 Elementor Widgets, GSAP Animations & Templates",
  "wordpress_org": "https://wordpress.org/plugins/happy-elementor-addons/",
  "advisories_url": "https://wpsec.com/vuln/plugin/happy-elementor-addons/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/happy-elementor-addons"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.4,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "3.14.0",
    "from_inclusive": true,
    "to": "3.50.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 3.14.0 before 3.50.1"
  ]
 },
 "introduced_in": "3.14.0",
 "fixed_in": "3.50.1",
 "remediation": "Update to 3.50.1 or later.",
 "fix_released": "2026-10-05T07:41:28+00:00",
 "published": "2026-10-06T07:42:22+00:00",
 "updated": "2026-10-05T10:38:59.038940+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0435/",
  "https://plugins.svn.wordpress.org/happy-elementor-addons/tags/3.50.1/",
  "https://wordpress.org/plugins/happy-elementor-addons/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/happy-elementor-addons",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "High",
  "affected_versions": "High",
  "as_of": "2026-10-06"
 }
}