Skip to main content

Vendor/product archive

hasthemes / ht_mega CVEs

Beta · best-effort

30 CVEs tagged to hasthemes / ht_mega1 Critical, 3 High, 26 Medium, 0 Low, 0 Unrated.

CVE-2025-8401

Published Jul 31, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8151

Published Jul 31, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9.1 via the 'save_block_css' function. Thi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8068

Published Jul 31, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajax_trash…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1802

Published Mar 20, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text'…

CVSS 6.4 · Medium
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2025-1261

Published Mar 8, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, an…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-12599

Published Feb 11, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and includin…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12597

Published Feb 4, 2025

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to,…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8910

Published Sep 25, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render functio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38706

Published Jul 12, 2024

Path Traversal: '.../...//' vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a through <= 2.5.7.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5215

Published Jun 26, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.5.5 due…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5173

Published Jun 26, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video player widget settings in all versions up to, and inclu…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4876

Published May 21, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popover_header_text’ parameter in versions up to, and includ…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4875

Published May 21, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'ajax_dis…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37999

Published May 17, 2024

Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-3990

Published May 14, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip & Popover Widget in all versions up to, and including…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3989

Published May 14, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gallery Justify Widget in all versions up to, and in…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3308

Published May 2, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget's attributes in all versions up to, and inc…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3307

Published May 2, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget's attributes in all versions up to, and incl…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2790

Published May 2, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Accordion widget in all versions up to, and including, 2.4.8 due…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2085

Published May 2, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' value in several widgets all versions up to, and inclu…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2084

Published May 2, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lightbox widget in all versions up to, and including…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6214

Published May 2, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_prod…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32782

Published Apr 24, 2024

Insertion of Sensitive Information Into Sent Data vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a through <= 2.4.7.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1974

Published Apr 9, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This mak…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30182

Published Mar 27, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 30 CVEsPage 1 of 2