Impact
An input validation flaw in weDevs Happy Addons for Elementor allows an attacker to inject arbitrary JavaScript that is rendered in the generated page. The stored XSS can be executed in the browsers of any user who views the affected content, enabling session hijacking, credential theft, defacement, or the launch of further attacks against the site. The flaw is reflected in the official description as an "Improper Neutralization of Input During Web Page Generation," which is the basis for the identified CWE-79 weakness.
Affected Systems
The vulnerability affects WordPress sites that use the weDevs Happy Addons for Elementor plugin, versions up through 3.50.0. Versions prior to 3.50.1 have not applied the necessary input sanitization to prevent the injection of malicious scripts.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalogue, suggesting a lower known exploitation impact at present. The likely attack vector is web‑based; an attacker can submit malicious content via the plugin’s input fields, which is then stored and served to all site visitors. If the site is publicly accessible, the risk of executing the payload and compromising user sessions is significant, especially if administrative or high‑privilege accounts are not protected by additional authentication mechanisms.
OpenCVE Enrichment