plugin

Ht Mega For Elementor Vulnerabilities

66 known security issues reported for the Ht Mega For Elementor WordPress plugin. Most recent disclosed Apr 24, 2026.

1 critical 2 high 30 medium

Running Ht Mega For Elementor on your site? Check whether your installed version is affected.

Scan your site free

HT Mega Addons for Elementor – Elementor Widgets & Template Builder < 3.0.7 - Unauthenticated Information Exposure

medium

The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 3.0.7 (exclusive). This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 3.0.7
Fixed in:
3.0.7
Disclosed:
Apr 24, 2026

CVE-2026-4106 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 3.0.1

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gutenberg blocks in all versions up to, and including, 3.0.0 due to insufficient input validation on user-supplied HTML tag names. This is due to the lack of a tag name whitelist allowing...

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Nov 21, 2025

CVE-2025-13141 on NVD →

HT Mega – Absolute Addons For Elementor <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tag Attribute Injection

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gutenberg blocks in all versions up to, and including, 3.0.0 due to insufficient input validation on user-supplied HTML tag names. This is due to the lack of a tag name whitelist allowing dange...

CVSS:
6.4
Affected:
up to 3.0.0
Fixed in:
3.0.1
Disclosed:
Nov 20, 2025

CVE-2025-13141 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.9.1

unknown

[en] Missing Authorization vulnerability in HasTech HT Mega allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HT Mega: from n/a through 2.9.0.

Affected:
up to 2.9.1
Fixed in:
2.9.1
Disclosed:
Aug 14, 2025

CVE-2025-54695 on NVD →

HT Mega <= 2.9.0 - Missing Authorization

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.9.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized actio...

CVSS:
4.3
Affected:
up to 2.9.0
Fixed in:
2.9.1
Disclosed:
Jul 30, 2025

CVE-2025-54695 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.9.1 - Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajax_trash_templates' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Contributor-level...

CVSS:
4.3
Affected:
up to 2.9.1
Fixed in:
2.9.2
Disclosed:
Jul 30, 2025

CVE-2025-8068 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Sensitive Information Exposure

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including the c...

CVSS:
4.3
Affected:
up to 2.9.1
Fixed in:
2.9.2
Disclosed:
Jul 30, 2025

CVE-2025-8401 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File Actions

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9.1 via the 'save_block_css' function. This makes it possible for authenticated attackers, with Author-level access and above, to create CSS files in any directory, and delete CSS fil...

CVSS:
4.3
Affected:
up to 2.9.1
Fixed in:
2.9.2
Disclosed:
Jul 30, 2025

CVE-2025-8151 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text' parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible fo...

CVSS:
6.4
Affected:
up to 2.8.3
Fixed in:
2.8.4
Disclosed:
Mar 19, 2025

CVE-2025-1802 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...

CVSS:
6.4
Affected:
up to 2.8.2
Fixed in:
2.8.3
Disclosed:
Mar 7, 2025

CVE-2025-1261 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.8.2

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate...

Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Feb 11, 2025

CVE-2024-12599 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...

CVSS:
6.4
Affected:
up to 2.8.1
Fixed in:
2.8.2
Disclosed:
Feb 10, 2025

CVE-2024-12599 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.7.7

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Affected:
up to 2.7.7
Fixed in:
2.7.7
Disclosed:
Feb 4, 2025

CVE-2024-12597 on NVD →

HT Mega <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner_css

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Co...

CVSS:
6.4
Affected:
up to 2.7.6
Fixed in:
2.7.7
Disclosed:
Feb 3, 2025

CVE-2024-12597 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.6.6

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render function in includes/widgets/htmega_accordion.php. This makes it possible for authenticated attackers, with Contributor-level access and above,...

Affected:
up to 2.6.6
Fixed in:
2.6.6
Disclosed:
Sep 25, 2024

CVE-2024-8910 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.6.5 - Authenticated (Contributor+) Sensitive Information Exposure via template_id

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render function in includes/widgets/htmega_accordion.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to e...

CVSS:
4.3
Affected:
up to 2.6.5
Fixed in:
2.6.6
Disclosed:
Sep 24, 2024

CVE-2024-8910 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.8

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HasThemes HT Mega allows Path Traversal.This issue affects HT Mega: from n/a through 2.5.7.

Affected:
up to 2.5.8
Fixed in:
2.5.8
Disclosed:
Jul 12, 2024

CVE-2024-38706 on NVD →

HT Mega <= 2.5.7 - Authenticated (Contributor+) JSON File Directory Traversal

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to perform actions on JSON files outside of the originally intended directory.

CVSS:
4.3
Affected:
up to 2.5.7
Fixed in:
2.5.8
Disclosed:
Jul 11, 2024

CVE-2024-38706 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.6

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...

Affected:
up to 2.5.6
Fixed in:
2.5.6
Disclosed:
Jun 26, 2024

CVE-2024-5215 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.6

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video player widget settings in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...

Affected:
up to 2.5.6
Fixed in:
2.5.6
Disclosed:
Jun 26, 2024

CVE-2024-5173 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 2.5.5
Fixed in:
2.5.6
Disclosed:
Jun 25, 2024

CVE-2024-5215 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Player Widget Settings

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video player widget settings in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 2.5.5
Fixed in:
2.5.6
Disclosed:
Jun 25, 2024

CVE-2024-5173 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.4.5 - Authenticated (Contributor+) Directory Traversal

high

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to read the contents of arbitrary files on the server, which c...

CVSS:
8.8
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
May 23, 2024

CVE-2024-1974 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.3

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popover_header_text’ parameter in versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribu...

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
May 21, 2024

CVE-2024-4876 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.3

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'ajax_dismiss' function in versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with subscriber-level permis...

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
May 21, 2024

CVE-2024-4875 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.5.2 - Missing Authorization to Options Update

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'ajax_dismiss' function in versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with subscriber-level permissions...

CVSS:
4.3
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
May 20, 2024

CVE-2024-4875 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popover_header_text’ parameter in versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-l...

CVSS:
6.4
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
May 20, 2024

CVE-2024-4876 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.2.1

unknown

[en] Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.

Affected:
up to 2.2.1
Fixed in:
2.2.1
Disclosed:
May 17, 2024

CVE-2023-37999 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.1

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gallery Justify Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen...

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
May 9, 2024

CVE-2024-3989 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.1

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip & Popover Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
May 9, 2024

CVE-2024-3990 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Justify

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gallery Justify Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat...

CVSS:
6.4
Affected:
up to 2.5.0
Fixed in:
2.5.1
Disclosed:
May 7, 2024

CVE-2024-3989 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tooltip & Popover Widget

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip & Popover Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...

CVSS:
6.4
Affected:
up to 2.5.0
Fixed in:
2.5.1
Disclosed:
May 7, 2024

CVE-2024-3990 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.9

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Accordion widget in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...

Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
May 2, 2024

CVE-2024-2790 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.0

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget's attributes in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contri...

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
May 2, 2024

CVE-2024-3307 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.7

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' value in several widgets all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...

Affected:
up to 2.4.7
Fixed in:
2.4.7
Disclosed:
May 2, 2024

CVE-2024-2085 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.7

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_products function. This makes it possible for unauthenticatied attackers to extract sensitive data including the previous 7 days of order da...

Affected:
up to 2.4.7
Fixed in:
2.4.7
Disclosed:
May 2, 2024

CVE-2023-6214 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.7

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lightbox widget in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

Affected:
up to 2.4.7
Fixed in:
2.4.7
Disclosed:
May 2, 2024

CVE-2024-2084 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.5.0

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget's attributes in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contr...

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
May 2, 2024

CVE-2024-3308 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.8

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HasThemes HT Mega.This issue affects HT Mega: from n/a through 2.4.7.

Affected:
up to 2.4.8
Fixed in:
2.4.8
Disclosed:
Apr 24, 2024

CVE-2024-32782 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.4.7 - Missing Authorization to Information Exposure

medium

The HT Mega plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the duplicate() function in all versions up to, and including, 2.4.7. This makes it possible for authenticated attackers, with contributor-level access and above, to duplicate arbitrary posts that ma...

CVSS:
4.3
Affected:
up to 2.4.7
Fixed in:
2.4.8
Disclosed:
Apr 22, 2024

CVE-2024-32782 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.4.6 - Sensitive Information Exposure via purchased_products

high

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_products function. This makes it possible for unauthenticatied attackers to extract sensitive data including the previous 7 days of order data in...

CVSS:
7.5
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
Apr 16, 2024

CVE-2023-6214 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Grid Widget

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget's attributes in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributo...

CVSS:
6.4
Affected:
up to 2.4.9
Fixed in:
2.5.0
Disclosed:
Apr 16, 2024

CVE-2024-3308 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lightbox Widget

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lightbox widget in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...

CVSS:
6.4
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
Apr 16, 2024

CVE-2024-2084 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget's attributes in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor...

CVSS:
6.4
Affected:
up to 2.4.9
Fixed in:
2.5.0
Disclosed:
Apr 16, 2024

CVE-2024-3307 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion/FAQ

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Accordion widget in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 2.4.8
Fixed in:
2.4.9
Disclosed:
Apr 16, 2024

CVE-2024-2790 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size'

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' value in several widgets all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
Apr 16, 2024

CVE-2024-2085 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.7

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to read the contents of arbitrary files on the server, wh...

Affected:
up to 2.4.7
Fixed in:
2.4.7
Disclosed:
Apr 9, 2024

CVE-2024-1974 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega allows Stored XSS.This issue affects HT Mega: from n/a through 2.4.3.

Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Mar 27, 2024

CVE-2024-30182 on NVD →

HT Mega <= 2.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The HT Mega plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wil...

CVSS:
6.4
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Mar 25, 2024

CVE-2024-30182 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Carousel Widget

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the Post Carousel widget in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...

CVSS:
6.4
Affected:
up to 2.4.4
Fixed in:
2.4.5
Disclosed:
Mar 12, 2024

CVE-2024-1421 on NVD →

HT Mega <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via titleTag

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on the 'titleTag' user supplied attributes. This makes it possible for authenticate...

CVSS:
6.4
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
Mar 12, 2024

CVE-2024-1397 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.7

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on the 'titleTag' user supplied attributes. This makes it possible for authent...

Affected:
up to 2.4.7
Fixed in:
2.4.7
Disclosed:
Mar 12, 2024

CVE-2024-1397 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.4.5

unknown

[en] The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the Post Carousel widget in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

Affected:
up to 2.4.5
Fixed in:
2.4.5
Disclosed:
Mar 12, 2024

CVE-2024-1421 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.3.4

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Mega – Absolute Addons For Elementor.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2.3.3.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Feb 29, 2024

CVE-2023-51529 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.3.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega – Absolute Addons For Elementor allows Reflected XSS.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2.3.8.

Affected:
up to 2.3.9
Fixed in:
2.3.9
Disclosed:
Dec 29, 2023

CVE-2023-50901 on NVD →

HT Mega <= 2.3.3 - Cross-Site Request Forgery via Several Functions

medium

The HT Mega plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions in the /admin/include/template-library.php file. This makes it possible for unauthenticated attackers to install and activate pl...

CVSS:
4.3
Affected:
up to 2.3.3
Fixed in:
2.3.4
Disclosed:
Dec 27, 2023

CVE-2023-51529 on NVD →

HT Mega – Absolute Addons For Elementor <= 2.3.8 - Reflected Cross-Site Scripting

medium

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reg_bio' parameter in all versions up to, and including, 2.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...

CVSS:
6.1
Affected:
up to 2.3.8
Fixed in:
2.3.9
Disclosed:
Dec 26, 2023

CVE-2023-50901 on NVD →

HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege Escalation

critical

The HT Mega plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.2.0. This is due to missing validation of the reg_role parameter on the htmega_ajax_register function. This makes it possible for unauthenticated attackers to create administrator accounts.

CVSS:
9.8
Affected:
up to 2.2.1
Fixed in:
2.2.1
Disclosed:
Jul 7, 2023

CVE-2023-37999 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 1.7.0

unknown

SQL injection (SQLi) vulnerability discovered in WordPress HT Mega plugin (versions <= 1.6.9).

Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Dec 20, 2021

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 1.5.7

unknown

[en] The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

Affected:
up to 1.5.7
Fixed in:
1.5.7
Disclosed:
May 5, 2021

CVE-2021-24261 on NVD →

HT Mega - Absolute Addons for Elementor Page Builder <= 1.5.5 - Contributor+ Stored Cross-Site Scripting

medium

The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVSS:
5.4
Affected:
up to 1.5.5
Fixed in:
1.5.7
Disclosed:
Apr 13, 2021

CVE-2021-24261 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.8.3

unknown
Affected:
up to 2.8.3
Fixed in:
2.8.3

CVE-2025-1261 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.8.4

unknown
Affected:
up to 2.8.4
Fixed in:
2.8.4

CVE-2025-1802 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.9.2

unknown
Affected:
up to 2.9.2
Fixed in:
2.9.2

CVE-2025-8151 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.9.2

unknown
Affected:
up to 2.9.2
Fixed in:
2.9.2

CVE-2025-8068 on NVD →

HT Mega &#8211; Absolute Addons For Elementor [ht-mega-for-elementor] < 2.9.2

unknown
Affected:
up to 2.9.2
Fixed in:
2.9.2

CVE-2025-8401 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database