Executive brief
HappyAddons for Elementor is a WordPress plugin that extends Elementor's page-builder capabilities with additional widgets. The plugin fails to properly escape icon values in a button widget, allowing contributors and higher-level users to inject malicious JavaScript code. When site visitors or administrators view pages with the infected widget, the injected code executes in their browsers, potentially compromising accounts or stealing sensitive data.
Technical details
A stored XSS vulnerability in the Creative Button widget stems from insufficient output escaping of an icon attribute before insertion into an HTML attribute context. The vulnerability requires Contributor-level access to the WordPress site and affects versions before 3.50.0. Attackers can inject event-handler attributes that execute arbitrary JavaScript when the page is viewed by any user, including administrators without unfiltered_html capability.
Affected products
- HappyAddons Happy Addons for Elementor before 3.50.0
Timeline
- 2026-09-21: disclosed
- 2026-09-21: patched: Fixed in version 3.50.0