CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-0438

Medium Severity|Leevio
30
SVRS
5.4
CVSSv3
0.00581
EPSS
TAGS
In The Wild
VECTOR STRING
CVSS:3.1AV:NAC:LPR:LUI:RS:CC:LI:LA:N
PUBLICATION DATE2024-02-20
LAST MODIFIED2026-04-08

Security Intelligence Brief

What is this vulnerability and why does it matter? This vulnerability (CVE-2024-0438) is a Stored Cross-Site Scripting (XSS) flaw found in the Happy Addons for Elementor plugin for WordPress. It exists due to insufficient input sanitization and output escaping of the 'wrapper link' parameter within the 'Age Gate' feature. This matters because it allows authenticated attackers with contributor access or higher to inject arbitrary web scripts into pages. When a user accesses an affected page, the injected script will execute in their browser, potentially leading to session hijacking, data theft, website defacement, or redirection to malicious sites.

What are the CVSS score, severity level, and disclosure details? The CVSS score for this vulnerability is 5.4. This translates to a Medium severity level. The vulnerability was published on 2024-02-20 18:56:23 and was last modified on 2026-04-08 16:42:43.

Which products, vendors, systems, and versions are affected? The affected product is the Happy Addons for Elementor plugin. It impacts WordPress systems. All versions of the Happy Addons for Elementor plugin up to, and including, 3.10.1 are vulnerable.

What is the technical root cause and attack vector? The technical root cause of this vulnerability is insufficient input sanitization and output escaping. The attack vector is specifically through the 'wrapper link' parameter within the 'Age Gate' feature of the Happy Addons for Elementor plugin.

How can this vulnerability be exploited? This vulnerability can be exploited by an authenticated attacker who has contributor access or higher privileges on the WordPress site. The attacker can inject arbitrary web scripts into the 'wrapper link' parameter of the Age Gate feature. Once injected, these scripts will be stored on the website and will execute in the browser of any user who accesses the page containing the malicious content.

What mitigation steps and patches are available? To mitigate this vulnerability, users should update the Happy Addons for Elementor plugin to a version beyond 3.10.1. It is critical to apply the latest available update provided by the vendor, as newer versions are expected to contain the necessary fixes for input sanitization and output escaping.

How can vulnerable systems be detected? Vulnerable systems can be detected by checking the installed version of the Happy Addons for Elementor plugin on a WordPress site. Any installation running version 3.10.1 or earlier is considered vulnerable to CVE-2024-0438.

What public intelligence references and advisories exist? The primary public intelligence reference for this vulnerability is CVE-2024-0438 itself. Additionally, CVE-2024-29108 is noted as a likely duplicate of this issue.

What is the risk assessment and urgency level? The risk assessment for CVE-2024-0438 is rated as Medium, based on its CVSS score of 5.4. Despite the medium severity, the urgency level for patching is high due to the nature of Stored Cross-Site Scripting vulnerabilities. These types of vulnerabilities can lead to significant impacts such as unauthorized access to user accounts, defacement of the website, information disclosure, and potentially broader compromise of the affected WordPress site and its users. The requirement for authenticated access (contributor or higher) slightly limits the attack surface but does not negate the critical need for immediate remediation, especially in environments where multiple users have publishing privileges.

No IOCs found for this CVE

No exploits found for this CVE

SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs
CVE-2024-0438 | Happy Addons for Elementor Plugin up to 3.10.1 on WordPress cross site scripting
vuldb.com2026-04-12
CVE-2024-0438 | Happy Addons for Elementor Plugin up to 3.10.1 on WordPress cross site scripting | A vulnerability classified as problematic was found in Happy Addons for Elementor Plugin up to 3.10.1 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting. This vulnerability is traded as CVE-2024-0438. The attack may be launched remotely. There is no exploit available.
cve-2024-0438wordpresshttpsunknown

No tweets found for this CVE

Configuration 1
TypeVendorProduct
AppLeeviohappy_addons_for_elementor
ReferenceLink
[email protected]https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.1/assets/js/happy-addons.js#L991
[email protected]https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.1/extensions/wrapper-link.php#L50
[email protected]https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3028056%40happy-elementor-addons%2Ftrunk&old=3016053%40happy-elementor-addons%2Ftrunk&sfp_email=&sfph_mail=
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/267641fe-7490-4b8f-bb39-9531eefa2c30?source=cve
AF854A3A-2127-422B-91AE-364DA2661108https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.1/assets/js/happy-addons.js#L991
AF854A3A-2127-422B-91AE-364DA2661108https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.1/extensions/wrapper-link.php#L50
AF854A3A-2127-422B-91AE-364DA2661108https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3028056%40happy-elementor-addons%2Ftrunk&old=3016053%40happy-elementor-addons%2Ftrunk&sfp_email=&sfph_mail=
AF854A3A-2127-422B-91AE-364DA2661108https://www.wordfence.com/threat-intel/vulnerabilities/id/267641fe-7490-4b8f-bb39-9531eefa2c30?source=cve
[email protected]https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.1/assets/js/happy-addons.js#L991
[email protected]https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.1/extensions/wrapper-link.php#L50
[email protected]https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3028056%40happy-elementor-addons%2Ftrunk&old=3016053%40happy-elementor-addons%2Ftrunk&sfp_email=&sfph_mail=
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/267641fe-7490-4b8f-bb39-9531eefa2c30?source=cve
AF854A3A-2127-422B-91AE-364DA2661108https://www.wordfence.com/threat-intel/vulnerabilities/id/267641fe-7490-4b8f-bb39-9531eefa2c30?source=cve
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/267641fe-7490-4b8f-bb39-9531eefa2c30?source=cve
CWE IDCWE NameDescription
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.