CVE-2024-2786: Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via title_tag
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on the titletag attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2786?
CVE-2024-2786 is classified as a medium severity vulnerability due to its potential to allow stored cross-site scripting attacks.
How do I fix CVE-2024-2786?
To fix CVE-2024-2786, update the Happy Addons for Elementor plugin to version 3.10.5 or later.
What versions of Happy Addons for Elementor are affected by CVE-2024-2786?
CVE-2024-2786 affects all versions of the Happy Addons for Elementor plugin up to and including version 3.10.4.
Who is impacted by CVE-2024-2786?
Authenticated attackers who have access to the WordPress site can exploit CVE-2024-2786 to execute malicious scripts.
What type of vulnerability is CVE-2024-2786?
CVE-2024-2786 is a stored cross-site scripting (XSS) vulnerability caused by insufficient input sanitization.