๐Ÿ” CVE Alert

CVE-2026-85006

UNKNOWN 0.0

Happy Addons for Elementor < 3.50.0 - Contributor+ Stored XSS via Creative Button Widget

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject event-handler attributes that execute JavaScript in the browser of anyone who views the page, including higher-privileged users reviewing the content, even though such users do not hold the unfiltered_html capability.

Vendor unknown
Product happyaddons for elementor
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for unknown happyaddons for elementor

Be the first to know when new unknown vulnerabilities affecting unknown happyaddons for elementor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / HappyAddons for Elementor
0 < 3.50.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/50319e24-8ae8-40b8-9106-ed881359700e/

Credits

Revanth Hari Narayana Matte WPScan