CVE-2026-2917General

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate_thing` admin action handler. This is due to the `can_clone()` method only checking `current_user_can('edit_posts')` (a general capability) without performing object-level authorization such as `current_user_can('edit_post', $post_id)`, and the nonce being tied to the generic action name `ha_duplicate_thing` rather than to a specific post ID. This makes it possible for authenticated attackers, with Contributor-level access and above, to clone any published post, page, or custom post type by obtaining a valid clone nonce from their own posts and changing the `post_id` parameter to target other users' content. The clone operation copies the full post content, all post metadata (including potentially sensitive widget configurations and API tokens), and taxonomies into a new draft owned by the attacker.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-11); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-11: 1Mentions · 2026-03-15: 1Technical Details · 2026-03-15: 103-1103-15
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-111
General1
2026-03-151
Disclosure1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2917 The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate… https://www.cve.org/CVERecord?id=CVE-2026-2917

    Post summary

    The Happy Addons for Elementor plugin is vulnerable to an Insecure Direct Object Reference in all versions up to 3.21.0, with no PoC, exploit, active exploitation, or patch information referenced.

    00000142
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-2917 Insecure Direct Object Reference in Happy Addons for Elementor WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2917

    Post summary

    The note references CVE-2026-2917 as an IDOR issue in Happy Addons for Elementor, but provides no additional context, PoC, exploit, or patch information.

    000009
    4.0K followersView on X

Explore more