← WordPress Vulnerabilities
WordPress security by component

HT Mega – Absolute Addons For Elementor

HT Mega – Absolute Addons For Elementor is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Mar 08, 2025; the highest CVE/CNA score is 6.4.

Plugin slug: ht-mega

CVE-2025-1261: HT Mega – Absolute Addons For Elementor: Cross-site scripting

HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedMar 08, 2025
Safe version guidanceSee mitigation notes
Safe version
Mar 08, 2025 CVE-2025-1261
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 11, 2025 CVE-2024-12599
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD6.1
Feb 04, 2025 CVE-2024-12597
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Sep 25, 2024 CVE-2024-8910
HT Mega – Absolute Addons For Elementor: Sensitive information exposure
HT Mega – Absolute Addons For Elementor is affected by sensitive information exposure. Exploitation requires at least contributor-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVDPending
May 14, 2024 CVE-2024-3989
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-3308
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-2790
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-2085
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-2084
HT Mega – Absolute Addons For Elementor: Cross-site scripting
HT Mega – Absolute Addons For Elementor is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 05, 2021 CVE-2021-24261
“HT Mega – Absolute Addons for Elementor Page Builder”: Cross-site scripting
“HT Mega – Absolute Addons for Elementor Page Builder” is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4