← WordPress Vulnerabilities
WordPress security by component

HT Mega

HT Mega is a WordPress component with 21 published CVE records in this archive. The latest tracked vulnerability was published Aug 14, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: ht-mega-for-elementor

CVE-2025-54695: HT Mega: A security weakness

HT Mega is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedAug 14, 2025
Safe version guidanceSee mitigation notes
Safe version
Aug 14, 2025 CVE-2025-54695
HT Mega: A security weakness
HT Mega is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Jul 31, 2025 CVE-2025-8401
HT Mega – Absolute Addons For Elementor: Sensitive information exposure
HT Mega – Absolute Addons For Elementor is affected by sensitive information exposure. Exploitation requires at least author-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVDPending
Jul 31, 2025 CVE-2025-8151
HT Mega – Absolute Addons For Elementor: Filesystem traversal
HT Mega – Absolute Addons For Elementor is affected by filesystem traversal. Exploitation requires at least author-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.3
NVDPending
Jul 31, 2025 CVE-2025-8068
HT Mega – Absolute Addons For Elementor: A security weakness
HT Mega – Absolute Addons For Elementor is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Mar 20, 2025 CVE-2025-1802
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jul 12, 2024 CVE-2024-38706
HT Mega: Filesystem traversal
HT Mega is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.5
NVD8.8
Jun 26, 2024 CVE-2024-5215
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 26, 2024 CVE-2024-5173
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 21, 2024 CVE-2024-4876
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 21, 2024 CVE-2024-4875
HT Mega – Absolute Addons For Elementor: A security weakness
HT Mega – Absolute Addons For Elementor is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
May 17, 2024 CVE-2023-37999
HT Mega: Privilege escalation or authentication bypass
HT Mega is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD9.8
May 14, 2024 CVE-2024-3990
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-3307
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2023-6214
HT Mega – Absolute Addons For Elementor: Sensitive information exposure
HT Mega – Absolute Addons For Elementor is affected by sensitive information exposure. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE7.5
NVDPending
Apr 24, 2024 CVE-2024-32782
HT Mega: A security weakness
HT Mega is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD6.5
Apr 09, 2024 CVE-2024-1974
HT Mega – Absolute Addons For Elementor: Filesystem traversal
HT Mega – Absolute Addons For Elementor is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVD6.5
Mar 27, 2024 CVE-2024-30182
HT Mega: Cross-site scripting
HT Mega is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 12, 2024 CVE-2024-1421
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 12, 2024 CVE-2024-1397
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 29, 2024 CVE-2023-51529
HT Mega – Absolute Addons For Elementor: Cross-site request forgery
HT Mega – Absolute Addons For Elementor is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Dec 29, 2023 CVE-2023-50901
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1