Impact
The vulnerability arises because the HappyAddons for Elementor button widget does not escape an icon value before placing it inside an HTML attribute. This allows a user with Contributor‑level access or higher to inject an event‑handler attribute that causes JavaScript to run in the browser of any user who views the page, even if that user has no unfiltered_html capability. The flaw is a stored cross‑site scripting issue (CWE‑79) and can lead to malicious code execution, defacement, or session hijacking for the site visitor.
Affected Systems
WordPress sites that have installed the HappyAddons for Elementor plugin before version 3.50.0. The plugin itself, listed by the CNA as "HappyAddons for Elementor," is the only affected product; no additional vendor or product details are supplied. Any WordPress installation running the unsupported plugin version is vulnerable.
Risk and Exploitability
The CVSS score is 6.8, indicating moderate severity. The EPSS score is listed as less than 1 %, suggesting a very low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires an attacker to obtain Contributor or higher level access on the WordPress site in order to inject the payload through the icon field. Once stored, the malicious code executes in the browsers of all viewable content, including editors and administrators, making the impact broad for the site’s audiences. Given the low public exploitation likelihood but straightforward attacker path, administrators should treat this as a high‑priority patch issue.
OpenCVE Enrichment