Sceawere
Vulnerability Detail
CVE-2026-62080UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Contributor XSS in Happy Addons
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- Leevio
- Product
- Happy Addons for Elementor
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-30T13:17:19.327Z",
"pubdate": "2026-09-30T13:17:19.327Z",
"executiveSummary": "A stored Cross-Site Scripting (XSS) vulnerability exists within the Happy Addons for Elementor plugin, affecting all versions up to and including 3.23.1.\nThe vulnerability originates from improper input sanitization and output escaping within the plugin's components, which allow authenticated users with Contributor-level privileges to inject malicious scripts.\nBy successfully exploiting this flaw, an attacker can execute arbitrary JavaScript in the context of an administrator's browser session.\nThe impact includes the potential for unauthorized administrative actions, account takeover, or redirection to malicious third-party websites.\nExploitation requires the attacker to possess at least Contributor-level access to the WordPress environment.\nThis vulnerability poses a significant security risk to the integrity and confidentiality of the affected WordPress site, as it leverages the trust of the administrator to facilitate malicious operations.",
"technicalDetails": "The vulnerability is categorized as Stored Cross-Site Scripting (XSS), stemming from the failure to adequately sanitize and validate user-supplied input before rendering it in the dashboard interface.\nSpecifically, the plugin fails to enforce proper context-aware output encoding on parameters processed by the Happy Addons widget configurations. When a user with Contributor-level access saves widget settings, the application stores the input containing malicious JavaScript payloads directly into the database.\nThe attack flow begins when the authenticated Contributor modifies a Happy Addons widget, embedding a crafted payload (e.g., <script>alert(document.cookie)</script>) into the affected fields. Because the input validation logic is insufficient, the payload is persisted without obstruction.\nSubsequently, when an administrative user accesses the specific page or dashboard area where the widget is rendered, the application renders the stored, unescaped payload directly into the DOM. This results in the execution of the script within the administrator's authenticated session.\nThis attack vector is particularly effective because it circumvents standard access controls by coercing the administrator to perform actions on behalf of the attacker. The vulnerability is restricted to environments where the Happy Addons for Elementor plugin (versions <= 3.23.1) is installed and active.\nBecause the payload is stored server-side, the attack does not require immediate interaction from the victim beyond simply viewing the administrative page where the compromised widget is loaded. The lack of proper nonce verification or restrictive input filtering for lower-privileged users allows for this privilege escalation scenario, wherein an attacker with minimal permissions (Contributor) influences the actions of an entity with higher permissions (Administrator). Post-exploitation, the attacker can leverage the victim's session to modify site content, create new administrative users, or execute additional server-side requests via the WordPress REST API or admin-ajax.php endpoints."
}