# HappyAddons for Elementor – 160 Elementor Widgets, GSAP Animations & Templates <= 3.50.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Bar Page Settings

- **ID:** WPSEC-2026-0435
- **Plugin:** HappyAddons for Elementor – 160 Elementor Widgets, GSAP Animations & Templates (`happy-elementor-addons`), https://wordpress.org/plugins/happy-elementor-addons/
- **Affected versions:** from 3.14.0 before 3.50.1
- **Fixed in:** 3.50.1 (Update to 3.50.1 or later.)
- **Severity:** Medium 6.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin High, affected versions High (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/happy-elementor-addons
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0435/

## Description

The HappyAddons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Reading Progress Bar page settings (ha_rpb_single_enable and ha_rpb_single_disable) in versions 3.14.0 up to, and including, 3.50.0 due to insufficient input sanitization and output escaping when these values are echoed into an inline JavaScript block in the Elementor editor preview. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts that execute when a user who can edit the page opens it in the Elementor editor.

## References

- https://wpsec.com/vuln/WPSEC-2026-0435/
- https://plugins.svn.wordpress.org/happy-elementor-addons/tags/3.50.1/
- https://wordpress.org/plugins/happy-elementor-addons/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0435/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
