Extension WordPress
Vulnérabilités HT Mega Addons for Elementor – Elementor Widgets & Template Builder
Cette page rassemble les failles publiées pour HT Mega Addons for Elementor – Elementor Widgets & Template Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de HT Mega Addons for Elementor – Elementor Widgets & Template Builder
33 fiches
HT Mega Addons for Elementor – Elementor Widgets & Template Builder < 3.0.7 – Unauthenticated Information Exposure
The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 3.0.7 (exclusive). This makes it possible for unauthenticated attackers to extract sensitive…
[*, 3.0.7)
3.0.7
24/04/2026
HT Mega – Absolute Addons For Elementor <= 3.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Tag Attribute Injection
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gutenberg blocks in all versions up to, and including, 3.0.0 due to insufficient input validation on user-supplied HTML…
*-3.0.0
3.0.1
20/11/2025
HT Mega <= 2.9.0 – Missing Authorization
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.9.0. This makes it possible for…
*-2.9.0
2.9.1
30/07/2025
HT Mega – Absolute Addons For Elementor <= 2.9.1 – Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajax_trash_templates' function in all versions up to, and including, 2.9.1.…
*-2.9.1
2.9.2
30/07/2025
HT Mega – Absolute Addons For Elementor <= 2.9.1 – Authenticated (Author+) Sensitive Information Exposure
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data' function. This makes it possible for authenticated attackers, with Author-level…
*-2.9.1
2.9.2
30/07/2025
HT Mega – Absolute Addons For Elementor <= 2.9.1 – Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File Actions
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9.1 via the 'save_block_css' function. This makes it possible for authenticated attackers, with Author-level access…
*-2.9.1
2.9.2
30/07/2025
HT Mega – Absolute Addons For Elementor <= 2.8.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text' parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and…
*-2.8.3
2.8.4
19/03/2025
HT Mega – Absolute Addons For Elementor <= 2.8.2 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output…
*-2.8.2
2.8.3
07/03/2025
HT Mega – Absolute Addons For Elementor <= 2.8.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping…
*-2.8.1
2.8.2
10/02/2025
HT Mega <= 2.7.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner_css
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output…
*-2.7.6
2.7.7
03/02/2025
HT Mega – Absolute Addons For Elementor <= 2.6.5 – Authenticated (Contributor+) Sensitive Information Exposure via template_id
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render function in includes/widgets/htmega_accordion.php. This makes it possible for authenticated attackers,…
*-2.6.5
2.6.6
24/09/2024
HT Mega <= 2.5.7 – Authenticated (Contributor+) JSON File Directory Traversal
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to perform actions on JSON files outside…
*-2.5.7
2.5.8
11/07/2024
HT Mega – Absolute Addons For Elementor <= 2.5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user…
*-2.5.5
2.5.6
25/06/2024
HT Mega – Absolute Addons For Elementor <= 2.5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Video Player Widget Settings
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video player widget settings in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output…
*-2.5.5
2.5.6
25/06/2024
HT Mega – Absolute Addons For Elementor <= 2.4.5 – Authenticated (Contributor+) Directory Traversal
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This makes it possible for authenticated attackers, with contributor access…
*-2.4.6
2.4.7
23/05/2024
HT Mega – Absolute Addons For Elementor <= 2.5.2 – Missing Authorization to Options Update
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'ajax_dismiss' function in versions up to, and including, 2.5.2. This…
*-2.5.2
2.5.3
20/05/2024
HT Mega – Absolute Addons For Elementor <= 2.5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popover_header_text’ parameter in versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes…
*-2.5.2
2.5.3
20/05/2024
HT Mega – Absolute Addons For Elementor <= 2.5.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Tooltip & Popover Widget
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip & Popover Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output…
*-2.5.0
2.5.1
07/05/2024
HT Mega – Absolute Addons For Elementor <= 2.5.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Justify
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gallery Justify Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output…
*-2.5.0
2.5.1
07/05/2024
HT Mega – Absolute Addons For Elementor <= 2.4.7 – Missing Authorization to Information Exposure
The HT Mega plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the duplicate() function in all versions up to, and including, 2.4.7. This makes it possible for authenticated attackers,…
*-2.4.7
2.4.8
22/04/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.