CVE
CVE-2026-2918 — Happy Addons for Elementor < 3.21.1 - Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-2918 | Happy Addons for Elementor < 3.21.1 - Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions | — | Unknown | < 3.21.1 | 3.21.1 | — | — |
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.