rootpwn

high · CVSS v3 6.8 · EPSS 0.00208

CVE-2026-85006

The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets …

Description

The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject event-handler attributes that execute JavaScript in the browser of anyone who views the page, including higher-privileged users reviewing the content, even though such users do not hold the unfiltered_html capability.

Scores

Severity
high
CVSS v2
8.3
CVSS v3
6.8
CVSS v4
EPSS
0.00208

← All CVEs