VendorsHasThemesht_megaall versions
Vulnerabilities

HasThemes HT Mega

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

30CVEs
CVE-2023-37999
WordPress HT Mega Absolute Addons for Elementor plugin <= 2.2.0 - Unauthenticated Privilege Escalation vulnerability
Published 2024-05-17 · Analyzed
9.8EPSS 0.033
CVE-2024-1974
HT Mega – Absolute Addons For Elementor <= 2.4.5 - Authenticated (Contributor+) Directory Traversal
Published 2024-04-09 · Modified
8.8EPSS 0.012
CVE-2024-38706
WordPress HT Mega plugin <= 2.5.7 - JSON Path Traversal vulnerability
Published 2024-07-12 · Modified
8.8EPSS 0.007
CVE-2023-51529
WordPress HT Mega Plugin <= 2.3.3 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2024-02-29 · Modified
8.8EPSS 0.002
CVE-2023-6214
HT Mega – Absolute Addons For Elementor <= 2.4.6 - Sensitive Information Exposure via purchased_products
Published 2024-05-02 · Modified
7.5EPSS 0.006
CVE-2023-50901
WordPress HT Mega Plugin <= 2.3.8 is vulnerable to Cross Site Scripting (XSS)
Published 2023-12-29 · Modified
7.1EPSS 0.004
CVE-2024-32782
WordPress HT Mega plugin <= 2.4.7 - Sensitive Data Exposure vulnerability
Published 2024-04-24 · Modified
6.5EPSS 0.009
CVE-2024-30182
WordPress HT Mega – Absolute Addons For Elementor plugin <= 2.4.3 - Cross Site Scripting (XSS) vulnerability
Published 2024-03-27 · Modified
6.5EPSS 0.004
CVE-2024-1397
HT Mega <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via titleTag
Published 2024-03-12 · Modified
6.4EPSS 0.005
CVE-2024-3990
HT Mega – Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tooltip & Popover Widget
Published 2024-05-09 · Modified
6.4EPSS 0.004
CVE-2024-3308
HT Mega – Absolute Addons For Elementor <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Grid Widget
Published 2024-05-02 · Modified
6.4EPSS 0.004
CVE-2024-5215
HT Mega – Absolute Addons For Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
Published 2024-06-26 · Modified
6.4EPSS 0.004
CVE-2024-4876
HT Mega – Absolute Addons For Elementor <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-05-21 · Modified
6.4EPSS 0.004
CVE-2024-3989
HT Mega – Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Justify
Published 2024-05-09 · Modified
6.4EPSS 0.003
CVE-2024-12599
HT Mega – Absolute Addons For Elementor <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
Published 2025-02-11 · Modified
6.4EPSS 0.003
CVE-2024-3307
HT Mega – Absolute Addons For Elementor <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
Published 2024-05-02 · Modified
6.4EPSS 0.003
CVE-2024-2790
HT Mega – Absolute Addons For Elementor <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion/FAQ
Published 2024-05-02 · Modified
6.4EPSS 0.003
CVE-2024-2085
HT Mega – Absolute Addons For Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size'
Published 2024-05-02 · Modified
6.4EPSS 0.003
CVE-2024-2084
HT Mega – Absolute Addons For Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lightbox Widget
Published 2024-05-02 · Modified
6.4EPSS 0.003
CVE-2024-1421
HT Mega – Absolute Addons For Elementor <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Carousel Widget
Published 2024-03-12 · Modified
6.4EPSS 0.003
CVE-2024-12597
HT Mega <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner_css
Published 2025-02-04 · Analyzed
6.4EPSS 0.003
CVE-2025-1802
HT Mega – Absolute Addons For Elementor <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
Published 2025-03-20 · Analyzed
6.4EPSS 0.003
CVE-2024-5173
HT Mega – Absolute Addons For Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Player Widget Settings
Published 2024-06-26 · Modified
6.4EPSS 0.003
CVE-2025-1261
HT Mega – Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget
Published 2025-03-08 · Analyzed
6.4EPSS 0.002
CVE-2021-24261
HT Mega - Absolute Addons for Elementor Page Builder < 1.5.7 - Contributor+ Stored XSS
Published 2021-05-05 · Modified
5.4EPSS 0.007
CVE-2024-4875
HT Mega – Absolute Addons For Elementor <= 2.5.2 - Missing Authorization to Options Update
Published 2024-05-21 · Modified
4.3EPSS 0.008
CVE-2025-8151
HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File Actions
Published 2025-07-31 · Analyzed
4.3EPSS 0.004
CVE-2025-8401
HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Sensitive Information Exposure
Published 2025-07-31 · Analyzed
4.3EPSS 0.003
CVE-2024-8910
HT Mega – Absolute Addons For Elementor <= 2.6.5 - Authenticated (Contributor+) Sensitive Information Exposure via template_id
Published 2024-09-25 · Analyzed
4.3EPSS 0.003
CVE-2025-8068
HT Mega – Absolute Addons For Elementor <= 2.9.1 - Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions
Published 2025-07-31 · Analyzed
4.3EPSS 0.003