CVE-2026-25468
Happy Addons for Elementor
Minimum safe version
3.21.1
Update to 3.21.1 or later to address 45 fixable vulnerabilities
Happy Addons for Elementor <= 3.20.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_elementor_data' Meta Field
Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions
Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter
Happy Addons for Elementor <= 3.20.4 - Authenticated (Contributor+) SQL Injection
CVE-2025-14635
CVE-2025-63077
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
CVE-2025-30766
CVE-2024-12852
CVE-2024-10538
CVE-2024-48045
CVE-2024-47357
WordPress Happy Addons for Elementor Plugin <= 3.12.2 is vulnerable to Sensitive Data Exposure
WordPress Happy Addons for Elementor Plugin <= 3.11.2 is vulnerable to Cross Site Scripting (XSS)
Happy Elementor Addons < 3.10.1 - Contributor+ Stored Cross-Site Scripting
WordPress Happy Addons for Elementor Plugin <= 3.11.1 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-5347
CVE-2024-5041
CVE-2024-5088
WordPress Happy Addons for Elementor Plugin <= 3.10.8 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-4391
CVE-2024-4478
CVE-2024-3890
CVE-2024-32698
CVE-2024-3891
CVE-2024-3724
CVE-2024-2787
CVE-2024-1498
CVE-2024-2788
CVE-2024-2786
CVE-2024-2789
WordPress Happy Addons for Elementor Plugin <= 3.10.4 is vulnerable to Sensitive Data Exposure
CVE-2024-29108
CVE-2024-1366
CVE-2024-1377
CVE-2024-0838
CVE-2024-0438
CVE-2024-24833
Happy Elementor Addons <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2023-6632
WordPress Happy Addons for Elementor Plugin <= 3.9.1.1 is vulnerable to Server Side Request Forgery (SSRF)
CVE-2023-28989
WordPress Happy Addons for Elementor Plugin <= 3.7.2 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2021-24292