Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Happy Addons for Elementor — Vulnerabilities & Security Advisories 40

All 40 CVE vulnerabilities found in Happy Addons for Elementor, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities affecting the Happy Addons for Elementor WordPress plugin. It aggregates known weaknesses related to the software, categorized by Common Weakness Enumeration (CWE) types such as cross-site scripting and improper access control. The collection covers advisory disclosures and security incidents reported between January 2021 and December 2024. Here, security professionals and site administrators can track the vendor's history of addressing these issues, understand the specific risk profiles associated with the plugin’s architecture, and review the chronological history of exploits. The data serves as a resource for assessing the overall security posture of the Happy Addons ecosystem without promoting any specific vendor narrative. By consolidating disparate reports into a single view, this page facilitates a deeper analysis of recurring flaws and the efficacy of past patch cycles. Users may explore how different vulnerability classes interact within the plugin’s feature set and evaluate the timeline of remediation efforts. This approach supports informed decision-making regarding plugin usage, update schedules, and risk mitigation strategies for websites relying on this Elementor addon. The information provided is intended strictly for technical assessment and does not constitute an endorsement or condemnation of the product’s overall quality.

Vendor: weDevs

CVE IDTitleCVSSSeverityPublished
CVE-2024-2788 Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title HTML Tag CWE-79 6.4 Medium2024-04-09
CVE-2024-2786 Happy Addons for Elementor <= 3.10.4 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via title_tag CWE-79 5.4 Medium2024-04-09
CVE-2024-29108 WordPress Happy Addons for Elementor plugin <= 3.10.1 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-03-19
CVE-2024-1377 Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Author Meta Widget CWE-79 6.4 Medium2024-03-07
CVE-2024-1366 Happy Addons for Elementor <= 3.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Archive Title Widget CWE-79 6.4 Medium2024-03-07
CVE-2024-0838 Happy Addons for Elementor <= 3.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-20
CVE-2024-0438 Happy Addons for Elementor <= 3.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-20
CVE-2023-51676 WordPress Happy Addons for Elementor Plugin <= 3.9.1.1 is vulnerable to Server Side Request Forgery (SSRF) CWE-918 4.9 Medium2023-12-29
CVE-2023-28989 WordPress Happy Addons for Elementor Plugin <= 3.8.2 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium2023-07-10
CVE-2021-24292 Happy Addons for Elementor Free < 2.24.0 and Pro < 1.17.0 - Contributor+ Stored XSS CWE-79 5.4 -2021-05-17

All 40 known CVE vulnerabilities affecting Happy Addons for Elementor with full Chinese analysis, references, and POCs where available.