Impact
The vulnerability is an improper neutralization of special elements used in an SQL command, allowing a blind SQL injection. This permits an attacker to craft malicious input that the plugin passes directly to the database, potentially revealing sensitive data or manipulating database contents. The weakness is classified as CWE-89 and poses a high risk to the confidentiality of the site’s data.
Affected Systems
HappyMonster’s Happy Addons for Elementor plugin version 3.20.4 and earlier are affected. Any installation of the plugin on a WordPress site using these versions is vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates a severe vulnerability, while the EPSS score of less than 1% suggests low overall exploitation probability at this time. The vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector involves supplying specially crafted user input to the plugin’s interface, which could be performed from the front‑end or via an authenticated administrator. Although a blind mode limits immediate data visibility, an attacker can still infer data through timing and error responses.
OpenCVE Enrichment