CVE-2026-104393: WordPress Happy Addons for Elementor plugin <= 3.50.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs Happy Addons for Elementor happy-elementor-addons allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.50.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
weDevs Happy Addons for Elementorto a version that resolves this vulnerability.Fixed in 3.50.1
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attack vector requires network access, low attack complexity, and low-level privileges. User interaction is also required.
What is the potential impact if exploitation succeeds?
The vulnerability can allow stored cross-site scripting and is rated medium severity with a 6.5 CVSS score. The supplied vector indicates low impact to confidentiality, integrity, and availability, with scope changed.
Which plugin versions are affected?
Happy Addons for Elementor versions through 3.50.0 are affected. The available data does not identify a fixed version.