Vulnerabilities > CVE-2021-24261 - Unspecified vulnerability in Hasthemes HT Mega
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
Vulnerable Configurations
References
- https://wpscan.com/vulnerability/0377705d-29e9-47db-a5bb-8acaf311a38f
- https://wpscan.com/vulnerability/0377705d-29e9-47db-a5bb-8acaf311a38f
- https://www.wordfence.com/blog/2021/04/recent-patches-rock-the-elementor-ecosystem/
- https://www.wordfence.com/blog/2021/04/recent-patches-rock-the-elementor-ecosystem/