The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 21,731 live websites that are affected by CVE-2024-5041.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 21,731 live websites (33.78% of Happy Elementor Addons install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 107 versions ( 83.59% of all versions) |
![]() | 6,267 websites |
![]() | 2,678 websites |
![]() | 1,759 websites |
![]() | 1,385 websites |
![]() | 911 websites |
![]() | 909 websites |
![]() | 639 websites |
![]() | 533 websites |
![]() | 529 websites |
![]() | 396 websites |
.com | 7,985 websites |
.com.br | 2,567 websites |
.de | 994 websites |
.org | 734 websites |
.pl | 719 websites |
.fr | 515 websites |
.ru | 481 websites |
.net | 394 websites |
.co.uk | 323 websites |
.it | 313 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********************.com | ![]() | *,*** | |
*********.com | ![]() | **,*** | |
*******.org | ![]() | **,*** | |
******.net | ![]() | **,*** | |
********.**.il | ![]() | **,*** | |
******.org | ![]() | **,*** | |
********.com | ![]() | **,*** | |
**********.jp | ![]() | ***,*** | |
************.com | ![]() | ***,*** | |
**********.net | ![]() | ***,*** |
FAQ