Extension WordPress

Vulnérabilités HT Mega Addons for Elementor – Elementor Widgets & Template Builder

Cette page rassemble les failles publiées pour HT Mega Addons for Elementor – Elementor Widgets & Template Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

33Vulnérabilités
1Critiques
33Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de HT Mega Addons for Elementor – Elementor Widgets & Template Builder

33 fiches

CVE-2026-4106 Moyenne · 5,3
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega Addons for Elementor – Elementor Widgets & Template Builder < 3.0.7 – Unauthenticated Information Exposure

The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 3.0.7 (exclusive). This makes it possible for unauthenticated attackers to extract sensitive…

Versions affectées

[*, 3.0.7)

Correctif

3.0.7

Publication

24/04/2026

CVE-2025-13141 Moyenne · 6,4
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 3.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Tag Attribute Injection

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gutenberg blocks in all versions up to, and including, 3.0.0 due to insufficient input validation on user-supplied HTML…

Versions affectées

*-3.0.0

Correctif

3.0.1

Publication

20/11/2025

CVE-2025-8068 Moyenne · 4,3
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.9.1 – Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajax_trash_templates' function in all versions up to, and including, 2.9.1.…

Versions affectées

*-2.9.1

Correctif

2.9.2

Publication

30/07/2025

CVE-2025-8401 Moyenne · 4,3
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.9.1 – Authenticated (Author+) Sensitive Information Exposure

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data' function. This makes it possible for authenticated attackers, with Author-level…

Versions affectées

*-2.9.1

Correctif

2.9.2

Publication

30/07/2025

CVE-2025-8151 Moyenne · 4,3
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.9.1 – Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File Actions

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9.1 via the 'save_block_css' function. This makes it possible for authenticated attackers, with Author-level access…

Versions affectées

*-2.9.1

Correctif

2.9.2

Publication

30/07/2025

CVE-2025-1802 Moyenne · 6,4
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.8.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text' parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and…

Versions affectées

*-2.8.3

Correctif

2.8.4

Publication

19/03/2025

CVE-2025-1261 Moyenne · 6,4
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.8.2 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output…

Versions affectées

*-2.8.2

Correctif

2.8.3

Publication

07/03/2025

CVE-2024-12599 Moyenne · 6,4
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.8.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping…

Versions affectées

*-2.8.1

Correctif

2.8.2

Publication

10/02/2025

CVE-2024-12597 Moyenne · 6,4
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega <= 2.7.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner_css

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output…

Versions affectées

*-2.7.6

Correctif

2.7.7

Publication

03/02/2025

CVE-2024-8910 Moyenne · 4,3
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.6.5 – Authenticated (Contributor+) Sensitive Information Exposure via template_id

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render function in includes/widgets/htmega_accordion.php. This makes it possible for authenticated attackers,…

Versions affectées

*-2.6.5

Correctif

2.6.6

Publication

24/09/2024

CVE-2024-38706 Moyenne · 4,3
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega <= 2.5.7 – Authenticated (Contributor+) JSON File Directory Traversal

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to perform actions on JSON files outside…

Versions affectées

*-2.5.7

Correctif

2.5.8

Publication

11/07/2024

CVE-2024-5215 Moyenne · 6,4
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-2.5.5

Correctif

2.5.6

Publication

25/06/2024

CVE-2024-5173 Moyenne · 6,4
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Video Player Widget Settings

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video player widget settings in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output…

Versions affectées

*-2.5.5

Correctif

2.5.6

Publication

25/06/2024

CVE-2024-1974 Élevée · 8,8
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.4.5 – Authenticated (Contributor+) Directory Traversal

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This makes it possible for authenticated attackers, with contributor access…

Versions affectées

*-2.4.6

Correctif

2.4.7

Publication

23/05/2024

CVE-2024-4875 Moyenne · 4,3
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.5.2 – Missing Authorization to Options Update

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'ajax_dismiss' function in versions up to, and including, 2.5.2. This…

Versions affectées

*-2.5.2

Correctif

2.5.3

Publication

20/05/2024

CVE-2024-4876 Moyenne · 6,4
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popover_header_text’ parameter in versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.5.2

Correctif

2.5.3

Publication

20/05/2024

CVE-2024-3990 Moyenne · 6,4
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.5.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Tooltip & Popover Widget

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip & Popover Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output…

Versions affectées

*-2.5.0

Correctif

2.5.1

Publication

07/05/2024

CVE-2024-3989 Moyenne · 6,4
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.5.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Justify

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gallery Justify Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output…

Versions affectées

*-2.5.0

Correctif

2.5.1

Publication

07/05/2024

CVE-2024-32782 Moyenne · 4,3
HT Mega Addons for Elementor – Elementor Widgets & Template Builder

HT Mega – Absolute Addons For Elementor <= 2.4.7 – Missing Authorization to Information Exposure

The HT Mega plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the duplicate() function in all versions up to, and including, 2.4.7. This makes it possible for authenticated attackers,…

Versions affectées

*-2.4.7

Correctif

2.4.8

Publication

22/04/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités