Vulnerabilities > Leevio

DATE CVE VULNERABILITY TITLE RISK
2024-11-12 CVE-2024-10538 Cross-site Scripting vulnerability in Leevio Happy Addons for Elementor
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.12.5 due to insufficient input sanitization and output escaping.
network
low complexity
leevio CWE-79
5.4
2024-11-01 CVE-2024-48045 Missing Authorization vulnerability in Leevio Happy Addons for Elementor
Missing Authorization vulnerability in Leevio Happy Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy Addons for Elementor: from n/a through 3.12.3.
network
low complexity
leevio CWE-862
8.8