HT Mega Addons for Elementor – Elementor Widgets & Template Builder < 3.0.7 - Unauthenticated Information Exposure
HT Mega Addons for Elementor – Elementor Widgets & Template Builder
Minimum safe version
3.0.7
Update to 3.0.7 or later to address 34 fixable vulnerabilities
CVE-2025-13141
CVE-2025-54695
HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Sensitive Information Exposure
HT Mega – Absolute Addons For Elementor <= 2.9.1 - Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions
HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File Actions
HT Mega – Absolute Addons For Elementor <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
HT Mega – Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget
CVE-2024-12599
CVE-2024-12597
CVE-2024-8910
CVE-2024-38706
CVE-2024-5215
CVE-2024-5173
CVE-2024-4876
CVE-2024-4875
CVE-2024-3989
CVE-2024-3990
CVE-2024-32782
CVE-2024-2790
CVE-2024-3307
CVE-2024-2085
CVE-2024-3308
CVE-2024-2084
CVE-2023-6214
CVE-2024-30182
HT Mega – Absolute Addons For Elementor <= 2.4.5 - Authenticated (Contributor+) Directory Traversal
CVE-2024-1397
CVE-2024-1421
WordPress HT Mega Plugin <= 2.3.8 is vulnerable to Cross Site Scripting (XSS)
WordPress HT Mega Plugin <= 2.3.3 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-37999
WordPress HT Mega plugin <= 1.6.9 - SQL injection (SQLi) vulnerability
CVE-2021-24261