SQL Injection Vulnerability in Happy Addons for Elementor by HappyMonster
CVE-2025-68999
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 January 2026
Badges
What is CVE-2025-68999?
A significant SQL injection vulnerability exists in the Happy Addons for Elementor plugin developed by HappyMonster. This flaw enables attackers to potentially execute unauthorized SQL commands by exploiting improper neutralization of special elements in SQL queries. Affected versions include all versions from n/a through 3.20.4. This vulnerability could lead to unauthorized data access and manipulation, emphasizing the need for users to update to the latest version immediately to prevent exploitation.
Affected Version(s)
Happy Addons for Elementor 0 <= 3.20.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved