Hasthemes

Ht Mega

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 02.05.2024 17:15:15
  • Zuletzt bearbeitet 28.01.2025 19:27:44

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lightbox widget in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on u...

  • EPSS 0.89%
  • Veröffentlicht 02.05.2024 17:15:07
  • Zuletzt bearbeitet 28.01.2025 19:28:35

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_products function. This makes it possible for unauthenticatied attackers to...

  • EPSS 3.75%
  • Veröffentlicht 24.04.2024 08:15:39
  • Zuletzt bearbeitet 22.01.2025 20:34:45

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HasThemes HT Mega.This issue affects HT Mega: from n/a through 2.4.7.

  • EPSS 2.61%
  • Veröffentlicht 09.04.2024 19:15:21
  • Zuletzt bearbeitet 22.01.2025 17:28:42

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This makes it possible for authenticated attackers, with contributor access or ...

  • EPSS 0.18%
  • Veröffentlicht 27.03.2024 12:15:12
  • Zuletzt bearbeitet 28.01.2025 20:39:34

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega allows Stored XSS.This issue affects HT Mega: from n/a through 2.4.3.

  • EPSS 0.18%
  • Veröffentlicht 12.03.2024 23:15:46
  • Zuletzt bearbeitet 22.01.2025 17:41:50

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the Post Carousel widget in all versions up to, and including, 2.4.4 due to insufficient input sanitizati...

  • EPSS 0.22%
  • Veröffentlicht 12.03.2024 23:15:46
  • Zuletzt bearbeitet 22.01.2025 17:41:19

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on the 'title...

  • EPSS 0.17%
  • Veröffentlicht 29.02.2024 05:15:08
  • Zuletzt bearbeitet 22.01.2025 16:21:12

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Mega – Absolute Addons For Elementor.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2.3.3.

  • EPSS 0.17%
  • Veröffentlicht 29.12.2023 11:15:08
  • Zuletzt bearbeitet 21.11.2024 08:37:30

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega – Absolute Addons For Elementor allows Reflected XSS.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through ...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 05.05.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:52:42

The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.