Happy Addons for Elementor Free < 2.24.0 and Pro < 1.17.0 - Contributor+ Stored XSS
CVE-2021-24292
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 17 May 2021
What is CVE-2021-24292?
The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The āCardā widget accepts a ātitle_tagā parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a āsave_builderā request with the āheading_tagā set to āscriptā, and the actual ātitleā parameter set to JavaScript to be executed within the script tags added by the āheading_tagā parameter.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Happy Addons for Elementor 2.24.0
Happy Addons Pro for Elementor 1.17.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved