HappyMonster Happy Addons for Elementor (happy-elementor-addons) contains an SQL injection vulnerability due to improper neutralization of special elements used in an SQL command. The flaw allows blind SQL injection against affected WordPress sites running the plugin in versions up to and including 3.20.4, enabling an attacker to influence backend database queries without direct query output in responses.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit PoC for CVE-2025-68999 affecting Happy Addons for Elementor <= 3.20.4 on WordPress. It contains two files: a README describing the vulnerability, impact, and usage, and a single Python exploit script (poc.py). The exploit is not part of a larger framework. The vulnerability is an authenticated second-order SQL injection in the plugin's clone functionality. A low-privileged authenticated user with Contributor-level access can create a post and store a malicious custom field name (meta_key). That value is safely written to the database initially, but later the plugin's clone routine reads it back and concatenates it into a raw SQL INSERT statement without escaping. This storage-and-trigger pattern makes it a second-order injection. The Python script automates the full attack chain: it logs into WordPress using supplied credentials, requests the new-post editor to obtain WordPress nonces, saves a draft post with a crafted metakeyinput payload, visits the posts list to extract the Happy Clone nonce, triggers the vulnerable clone action through /wp-admin/admin.php?action=ha_duplicate_thing, then opens the cloned post and searches for a leaked custom field named leaked_hash. The hardcoded SQL payload extracts the admin user's password hash from the wp_users table and writes it to hash.txt. Primary capability: authenticated data extraction from the WordPress database via SQL injection, specifically demonstrated by exfiltrating the admin password hash. The README also notes the vulnerability could be adapted to read other sensitive data such as WordPress salts, wp_options secrets, and private post content. Because the payload is hardcoded and focused on one extraction goal, the exploit is best classified as OPERATIONAL rather than fully weaponized.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.