HT Mega Addons for Elementor – Elementor Widgets & Template Builder < 3.0.7 - Unauthenticated Information Exposure
medium
The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 3.0.7 (exclusive). This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.7
- Disclosed:
- Apr 24, 2026
CVE-2026-4106 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 3.0.1
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gutenberg blocks in all versions up to, and including, 3.0.0 due to insufficient input validation on user-supplied HTML tag names. This is due to the lack of a tag name whitelist allowing...
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
- Disclosed:
- Nov 21, 2025
CVE-2025-13141 on NVD →
HT Mega – Absolute Addons For Elementor <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tag Attribute Injection
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gutenberg blocks in all versions up to, and including, 3.0.0 due to insufficient input validation on user-supplied HTML tag names. This is due to the lack of a tag name whitelist allowing dange...
- CVSS:
- 6.4
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.1
- Disclosed:
- Nov 20, 2025
CVE-2025-13141 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.9.1
unknown
[en] Missing Authorization vulnerability in HasTech HT Mega allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HT Mega: from n/a through 2.9.0.
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
- Disclosed:
- Aug 14, 2025
CVE-2025-54695 on NVD →
HT Mega <= 2.9.0 - Missing Authorization
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.9.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized actio...
- CVSS:
- 4.3
- Affected:
- up to 2.9.0
- Fixed in:
- 2.9.1
- Disclosed:
- Jul 30, 2025
CVE-2025-54695 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.9.1 - Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajax_trash_templates' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Contributor-level...
- CVSS:
- 4.3
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.2
- Disclosed:
- Jul 30, 2025
CVE-2025-8068 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Sensitive Information Exposure
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including the c...
- CVSS:
- 4.3
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.2
- Disclosed:
- Jul 30, 2025
CVE-2025-8401 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File Actions
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9.1 via the 'save_block_css' function. This makes it possible for authenticated attackers, with Author-level access and above, to create CSS files in any directory, and delete CSS fil...
- CVSS:
- 4.3
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.2
- Disclosed:
- Jul 30, 2025
CVE-2025-8151 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text' parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible fo...
- CVSS:
- 6.4
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.4
- Disclosed:
- Mar 19, 2025
CVE-2025-1802 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...
- CVSS:
- 6.4
- Affected:
- up to 2.8.2
- Fixed in:
- 2.8.3
- Disclosed:
- Mar 7, 2025
CVE-2025-1261 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.8.2
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate...
- Affected:
- up to 2.8.2
- Fixed in:
- 2.8.2
- Disclosed:
- Feb 11, 2025
CVE-2024-12599 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...
- CVSS:
- 6.4
- Affected:
- up to 2.8.1
- Fixed in:
- 2.8.2
- Disclosed:
- Feb 10, 2025
CVE-2024-12599 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.7.7
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- Affected:
- up to 2.7.7
- Fixed in:
- 2.7.7
- Disclosed:
- Feb 4, 2025
CVE-2024-12597 on NVD →
HT Mega <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner_css
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Co...
- CVSS:
- 6.4
- Affected:
- up to 2.7.6
- Fixed in:
- 2.7.7
- Disclosed:
- Feb 3, 2025
CVE-2024-12597 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.6.6
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render function in includes/widgets/htmega_accordion.php. This makes it possible for authenticated attackers, with Contributor-level access and above,...
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.6
- Disclosed:
- Sep 25, 2024
CVE-2024-8910 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.6.5 - Authenticated (Contributor+) Sensitive Information Exposure via template_id
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render function in includes/widgets/htmega_accordion.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to e...
- CVSS:
- 4.3
- Affected:
- up to 2.6.5
- Fixed in:
- 2.6.6
- Disclosed:
- Sep 24, 2024
CVE-2024-8910 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.8
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HasThemes HT Mega allows Path Traversal.This issue affects HT Mega: from n/a through 2.5.7.
- Affected:
- up to 2.5.8
- Fixed in:
- 2.5.8
- Disclosed:
- Jul 12, 2024
CVE-2024-38706 on NVD →
HT Mega <= 2.5.7 - Authenticated (Contributor+) JSON File Directory Traversal
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to perform actions on JSON files outside of the originally intended directory.
- CVSS:
- 4.3
- Affected:
- up to 2.5.7
- Fixed in:
- 2.5.8
- Disclosed:
- Jul 11, 2024
CVE-2024-38706 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.6
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.6
- Disclosed:
- Jun 26, 2024
CVE-2024-5215 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.6
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video player widget settings in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.6
- Disclosed:
- Jun 26, 2024
CVE-2024-5173 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 2.5.5
- Fixed in:
- 2.5.6
- Disclosed:
- Jun 25, 2024
CVE-2024-5215 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Player Widget Settings
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video player widget settings in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 2.5.5
- Fixed in:
- 2.5.6
- Disclosed:
- Jun 25, 2024
CVE-2024-5173 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.4.5 - Authenticated (Contributor+) Directory Traversal
high
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to read the contents of arbitrary files on the server, which c...
- CVSS:
- 8.8
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.7
- Disclosed:
- May 23, 2024
CVE-2024-1974 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.3
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popover_header_text’ parameter in versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribu...
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.3
- Disclosed:
- May 21, 2024
CVE-2024-4876 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.3
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'ajax_dismiss' function in versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with subscriber-level permis...
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.3
- Disclosed:
- May 21, 2024
CVE-2024-4875 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.5.2 - Missing Authorization to Options Update
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'ajax_dismiss' function in versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with subscriber-level permissions...
- CVSS:
- 4.3
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- May 20, 2024
CVE-2024-4875 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popover_header_text’ parameter in versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- May 20, 2024
CVE-2024-4876 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.2.1
unknown
[en] Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- May 17, 2024
CVE-2023-37999 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.1
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gallery Justify Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen...
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.1
- Disclosed:
- May 9, 2024
CVE-2024-3989 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.1
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip & Popover Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.1
- Disclosed:
- May 9, 2024
CVE-2024-3990 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Justify
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gallery Justify Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat...
- CVSS:
- 6.4
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- May 7, 2024
CVE-2024-3989 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tooltip & Popover Widget
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip & Popover Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...
- CVSS:
- 6.4
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- May 7, 2024
CVE-2024-3990 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.9
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Accordion widget in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- Affected:
- up to 2.4.9
- Fixed in:
- 2.4.9
- Disclosed:
- May 2, 2024
CVE-2024-2790 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.0
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget's attributes in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contri...
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.0
- Disclosed:
- May 2, 2024
CVE-2024-3307 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.7
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' value in several widgets all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
- Disclosed:
- May 2, 2024
CVE-2024-2085 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.7
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_products function. This makes it possible for unauthenticatied attackers to extract sensitive data including the previous 7 days of order da...
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
- Disclosed:
- May 2, 2024
CVE-2023-6214 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.7
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lightbox widget in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
- Disclosed:
- May 2, 2024
CVE-2024-2084 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.0
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget's attributes in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contr...
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.0
- Disclosed:
- May 2, 2024
CVE-2024-3308 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.8
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HasThemes HT Mega.This issue affects HT Mega: from n/a through 2.4.7.
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.8
- Disclosed:
- Apr 24, 2024
CVE-2024-32782 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.4.7 - Missing Authorization to Information Exposure
medium
The HT Mega plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the duplicate() function in all versions up to, and including, 2.4.7. This makes it possible for authenticated attackers, with contributor-level access and above, to duplicate arbitrary posts that ma...
- CVSS:
- 4.3
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.8
- Disclosed:
- Apr 22, 2024
CVE-2024-32782 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.4.6 - Sensitive Information Exposure via purchased_products
high
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_products function. This makes it possible for unauthenticatied attackers to extract sensitive data including the previous 7 days of order data in...
- CVSS:
- 7.5
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.7
- Disclosed:
- Apr 16, 2024
CVE-2023-6214 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Grid Widget
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget's attributes in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributo...
- CVSS:
- 6.4
- Affected:
- up to 2.4.9
- Fixed in:
- 2.5.0
- Disclosed:
- Apr 16, 2024
CVE-2024-3308 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lightbox Widget
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lightbox widget in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...
- CVSS:
- 6.4
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.7
- Disclosed:
- Apr 16, 2024
CVE-2024-2084 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget's attributes in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor...
- CVSS:
- 6.4
- Affected:
- up to 2.4.9
- Fixed in:
- 2.5.0
- Disclosed:
- Apr 16, 2024
CVE-2024-3307 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion/FAQ
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Accordion widget in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.9
- Disclosed:
- Apr 16, 2024
CVE-2024-2790 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size'
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' value in several widgets all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.7
- Disclosed:
- Apr 16, 2024
CVE-2024-2085 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.7
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to read the contents of arbitrary files on the server, wh...
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
- Disclosed:
- Apr 9, 2024
CVE-2024-1974 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega allows Stored XSS.This issue affects HT Mega: from n/a through 2.4.3.
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.4
- Disclosed:
- Mar 27, 2024
CVE-2024-30182 on NVD →
HT Mega <= 2.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The HT Mega plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.4
- Disclosed:
- Mar 25, 2024
CVE-2024-30182 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Carousel Widget
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the Post Carousel widget in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...
- CVSS:
- 6.4
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.5
- Disclosed:
- Mar 12, 2024
CVE-2024-1421 on NVD →
HT Mega <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via titleTag
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on the 'titleTag' user supplied attributes. This makes it possible for authenticate...
- CVSS:
- 6.4
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.7
- Disclosed:
- Mar 12, 2024
CVE-2024-1397 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.7
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on the 'titleTag' user supplied attributes. This makes it possible for authent...
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
- Disclosed:
- Mar 12, 2024
CVE-2024-1397 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.5
unknown
[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the Post Carousel widget in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- Affected:
- up to 2.4.5
- Fixed in:
- 2.4.5
- Disclosed:
- Mar 12, 2024
CVE-2024-1421 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.3.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Mega – Absolute Addons For Elementor.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2.3.3.
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Feb 29, 2024
CVE-2023-51529 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.3.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega – Absolute Addons For Elementor allows Reflected XSS.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2.3.8.
- Affected:
- up to 2.3.9
- Fixed in:
- 2.3.9
- Disclosed:
- Dec 29, 2023
CVE-2023-50901 on NVD →
HT Mega <= 2.3.3 - Cross-Site Request Forgery via Several Functions
medium
The HT Mega plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions in the /admin/include/template-library.php file. This makes it possible for unauthenticated attackers to install and activate pl...
- CVSS:
- 4.3
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.4
- Disclosed:
- Dec 27, 2023
CVE-2023-51529 on NVD →
HT Mega – Absolute Addons For Elementor <= 2.3.8 - Reflected Cross-Site Scripting
medium
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reg_bio' parameter in all versions up to, and including, 2.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...
- CVSS:
- 6.1
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.9
- Disclosed:
- Dec 26, 2023
CVE-2023-50901 on NVD →
HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege Escalation
critical
The HT Mega plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.2.0. This is due to missing validation of the reg_role parameter on the htmega_ajax_register function. This makes it possible for unauthenticated attackers to create administrator accounts.
- CVSS:
- 9.8
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Jul 7, 2023
CVE-2023-37999 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 1.7.0
unknown
SQL injection (SQLi) vulnerability discovered in WordPress HT Mega plugin (versions <= 1.6.9).
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Dec 20, 2021
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 1.5.7
unknown
[en] The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.7
- Disclosed:
- May 5, 2021
CVE-2021-24261 on NVD →
HT Mega - Absolute Addons for Elementor Page Builder <= 1.5.5 - Contributor+ Stored Cross-Site Scripting
medium
The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
- CVSS:
- 5.4
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.7
- Disclosed:
- Apr 13, 2021
CVE-2021-24261 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.8.3
unknown
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
CVE-2025-1261 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.8.4
unknown
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
CVE-2025-1802 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.9.2
unknown
- Affected:
- up to 2.9.2
- Fixed in:
- 2.9.2
CVE-2025-8151 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.9.2
unknown
- Affected:
- up to 2.9.2
- Fixed in:
- 2.9.2
CVE-2025-8068 on NVD →
HT Mega – Absolute Addons For Elementor [ht-mega-for-elementor] < 2.9.2
unknown
- Affected:
- up to 2.9.2
- Fixed in:
- 2.9.2
CVE-2025-8401 on NVD →