Cross-Site Scripting
32 records72.7%First: 2021. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 44 vulnerability records associated with Happy Addons for Elementor, published between 2021 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2021 | 1 | |
| 2022 | 2 | |
| 2023 | 2 | |
| 2024 | 29 | |
| 2025 | 5 | |
| 2026 | 5 |
| Severity | Records | Share |
|---|---|---|
| Medium | 44 | 100% |
First: 2021. Latest: 2026.
First: 2022. Latest: 2026.
First: 2022. Latest: 2023.
First: 2024. Latest: 2026.
First: 2023. Latest: 2023.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.21.03.21.13.20.83.20.63.20.43.16.33.15.23.12.63.12.43.12.13.12.33.11.33.11.23.11.03.10.93.10.83.10.73.10.63.10.53.10.43.10.23.10.13.10.03.8.32.24.0Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.20.8 | Happy Addons for Elementor <= 3.20.8 - Unauthenticated Information Exposure | May 7, 2026 | 3.21.0 | Medium |
*-3.21.0 | Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter | March 10, 2026 | 3.21.1 | Medium |
*-3.21.0 | Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions | March 10, 2026 | 3.21.1 | Medium |
*-3.20.7 | Happy Addons for Elementor <= 3.20.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_elementor_data' Meta Field | February 2, 2026 | 3.20.8 | Medium |
*-3.20.4 | Happy Addons for Elementor <= 3.20.4 - Authenticated (Contributor+) SQL Injection | January 23, 2026 | 3.20.6 | Medium |
*-3.20.3 | Happy Addons for Elementor <= 3.20.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS | December 22, 2025 | 3.20.4 | Medium |
*-3.20.3 | Happy Addons for Elementor <= 3.20.3 - Missing Authorization | December 4, 2025 | 3.20.4 | Medium |
*-3.12.2 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library | July 2, 2025 | 3.12.3 | Medium |
*-3.16.2 | Happy Addons for Elementor <= 3.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | March 27, 2025 | 3.16.3 | Medium |
*-3.15.1 | Happy Addons for Elementor <= 3.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | January 7, 2025 | 3.15.2 | Medium |
*-3.12.5 | Happy Addons for Elementor <= 3.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison | November 11, 2024 | 3.12.6 | Medium |
*-3.12.3 | Happy Addons for Elementor <= 3.12.3 - Missing Authorization | October 13, 2024 | 3.12.4 | Medium |
*-3.12.0 | Happy Addons for Elementor <= 3.12.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | September 30, 2024 | 3.12.1 | Medium |
*-3.12.2 | Happy Addons for Elementor <= 3.12.2 - Authenticated (Contributor+) Sensitive Information Exposure | September 23, 2024 | 3.12.3 | Medium |
*-3.11.2 | Happy Addons for Elementor <= 3.11.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via PDF View Widget | July 26, 2024 | 3.11.3 | Medium |
*-3.11.1 | Happy Addons for Elementor <= 3.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gradient Heading Widget | June 28, 2024 | 3.11.2 | Medium |
*-3.10.9 | Happy Addons for Elementor <= 3.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation Widget | May 30, 2024 | 3.11.0 | Medium |
*-3.10.9 | Happy Addons for Elementor <= 3.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion | May 30, 2024 | 3.11.0 | Medium |
*-3.10.8 | Happy Addons for Elementor <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via _id Parameter | May 17, 2024 | 3.10.9 | Medium |
*-3.10.8 | Happy Addons for Elementor <= 3.10.8 - Authenticated (Contributor+) Stored Cross-Site Scripting | May 17, 2024 | 3.10.9 | Medium |
*-3.10.7 | Happy Addons for Elementor Authenticated (Contributor+) Stored-XSS <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar Widget | May 15, 2024 | 3.10.8 | Medium |
*-3.10.7 | Happy Addons for Elementor <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group Widget | May 15, 2024 | 3.10.8 | Medium |
*-3.10.6 | Happy Addons for Elementor <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Calendly Widget | April 25, 2024 | 3.10.7 | Medium |
*-3.10.5 | Happy Addons for Elementor <= 3.10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags | April 19, 2024 | 3.10.6 | Medium |
*-3.10.4 | Happy Addons for Elementor <= 3.10.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group, Photo Stack, & Horizontal Timeline | April 19, 2024 | 3.10.5 | Medium |
Selected source records
Published: May 7, 2026
Published: March 10, 2026
Published: March 10, 2026
Published: February 2, 2026
Published: January 23, 2026
Published: December 22, 2025
Published: December 4, 2025
Published: July 2, 2025
Published: January 23, 2026
Published: March 6, 2024
Published: January 9, 2024
Published: December 22, 2025
Published: March 10, 2026
Published: May 17, 2024
Published: April 25, 2024
Published: February 13, 2024
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.