Vulnerability in Happy Addons for Elementor — CVE-2026-62080
MediumSeverity
—Estimated exploit probability
400,000+ sitesInstalls
3.50.0Fixed in
What to do now
Update Happy Addons for Elementor to 3.50.0 or later.
Affected versions
- Everything up to and including 3.23.1
Affected: Happy Addons for Elementor (plugin, happy-elementor-addons)
What the vulnerability is
The HappyAddons for Elementor – 160 Elementor Widgets, GSAP Animations & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.23.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.