Sceawere

Vulnerability Detail

CVE-2026-62080UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Contributor XSS in Happy Addons

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Leevio
Product
Happy Addons for Elementor
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-30T13:17:19.327Z",
  "pubdate": "2026-09-30T13:17:19.327Z",
  "executiveSummary": "A stored Cross-Site Scripting (XSS) vulnerability exists within the Happy Addons for Elementor plugin, affecting all versions up to and including 3.23.1.\nThe vulnerability originates from improper input sanitization and output escaping within the plugin's components, which allow authenticated users with Contributor-level privileges to inject malicious scripts.\nBy successfully exploiting this flaw, an attacker can execute arbitrary JavaScript in the context of an administrator's browser session.\nThe impact includes the potential for unauthorized administrative actions, account takeover, or redirection to malicious third-party websites.\nExploitation requires the attacker to possess at least Contributor-level access to the WordPress environment.\nThis vulnerability poses a significant security risk to the integrity and confidentiality of the affected WordPress site, as it leverages the trust of the administrator to facilitate malicious operations.",
  "technicalDetails": "The vulnerability is categorized as Stored Cross-Site Scripting (XSS), stemming from the failure to adequately sanitize and validate user-supplied input before rendering it in the dashboard interface.\nSpecifically, the plugin fails to enforce proper context-aware output encoding on parameters processed by the Happy Addons widget configurations. When a user with Contributor-level access saves widget settings, the application stores the input containing malicious JavaScript payloads directly into the database.\nThe attack flow begins when the authenticated Contributor modifies a Happy Addons widget, embedding a crafted payload (e.g., <script>alert(document.cookie)</script>) into the affected fields. Because the input validation logic is insufficient, the payload is persisted without obstruction.\nSubsequently, when an administrative user accesses the specific page or dashboard area where the widget is rendered, the application renders the stored, unescaped payload directly into the DOM. This results in the execution of the script within the administrator's authenticated session.\nThis attack vector is particularly effective because it circumvents standard access controls by coercing the administrator to perform actions on behalf of the attacker. The vulnerability is restricted to environments where the Happy Addons for Elementor plugin (versions <= 3.23.1) is installed and active.\nBecause the payload is stored server-side, the attack does not require immediate interaction from the victim beyond simply viewing the administrative page where the compromised widget is loaded. The lack of proper nonce verification or restrictive input filtering for lower-privileged users allows for this privilege escalation scenario, wherein an attacker with minimal permissions (Contributor) influences the actions of an entity with higher permissions (Administrator). Post-exploitation, the attacker can leverage the victim's session to modify site content, create new administrative users, or execute additional server-side requests via the WordPress REST API or admin-ajax.php endpoints."
}
CVE-2026-62080: Contributor XSS in Happy Addons (MEDIUM Severity, CVSS: 6.5) | Sceawere