---
id: CVE-2026-85006
title: >-
  The HappyAddons for Elementor  WordPress plugin before 3.50.0 does not escape
  an icon value on one of its button widgets before outputting it inside an HTML
  attribute, allowing users with Contributor-level access and above to inject
  even…
summary: >-
  The HappyAddons for Elementor  WordPress plugin before 3.50.0 does not escape
  an icon value on one of its button widgets before outputting it inside an HTML
  attribute, allowing users with Contributor-level access and above to inject
  even…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: HappyAddons for Elementor
affected:
  - happyaddons_for_elementor < 3.50.0
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:13:31.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85006'
references:
  - url: 'https://wpscan.com/vulnerability/50319e24-8ae8-40b8-9106-ed881359700e/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00235
epssPercentile: 0.13063
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-23T10:42:01.226496Z'
ingestedAt: '2026-09-23T06:17:57.892Z'
---

## Overview

The HappyAddons for Elementor  WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an HTML attribute, allowing users with Contributor-level access and above to inject event-handler attributes that execute JavaScript in the browser of anyone who views the page, including higher-privileged users reviewing the content, even though such users do not hold the unfiltered_html capability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
