The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in widgets in all versions up to, and including, 3.10.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 19,846 live websites that are affected by CVE-2024-3891.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 19,846 live websites (30.85% of Happy Elementor Addons install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 103 versions ( 80.47% of all versions) |
![]() | 5,722 websites |
![]() | 2,292 websites |
![]() | 1,618 websites |
![]() | 1,303 websites |
![]() | 865 websites |
![]() | 806 websites |
![]() | 607 websites |
![]() | 488 websites |
![]() | 482 websites |
![]() | 356 websites |
.com | 7,183 websites |
.com.br | 2,327 websites |
.de | 883 websites |
.pl | 679 websites |
.org | 671 websites |
.fr | 485 websites |
.ru | 457 websites |
.net | 351 websites |
.co.uk | 299 websites |
.it | 290 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********************.com | ![]() | *,*** | |
*********.com | ![]() | **,*** | |
*******.org | ![]() | **,*** | |
******.net | ![]() | **,*** | |
********.**.il | ![]() | **,*** | |
******.org | ![]() | **,*** | |
********.com | ![]() | **,*** | |
**********.jp | ![]() | ***,*** | |
************.com | ![]() | ***,*** | |
**********.net | ![]() | ***,*** |
FAQ