Vulnerabilities > Leevio > Happy Addons FOR Elementor > 3.12.4

DATE CVE VULNERABILITY TITLE RISK
2024-11-12 CVE-2024-10538 Cross-site Scripting vulnerability in Leevio Happy Addons for Elementor
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.12.5 due to insufficient input sanitization and output escaping.
network
low complexity
leevio CWE-79
5.4