Vulnerabilities > Hasthemes

DATE CVE VULNERABILITY TITLE RISK
2024-05-14 CVE-2024-3990 Cross-site Scripting vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip & Popover Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
hasthemes CWE-79
5.4
2024-05-02 CVE-2024-2084 Cross-site Scripting vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lightbox widget in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
hasthemes CWE-79
5.4
2024-05-02 CVE-2024-2085 Cross-site Scripting vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' value in several widgets all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
hasthemes CWE-79
5.4
2024-05-02 CVE-2024-2790 Cross-site Scripting vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Accordion widget in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
hasthemes CWE-79
5.4
2024-05-02 CVE-2024-3307 Cross-site Scripting vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget's attributes in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping.
network
low complexity
hasthemes CWE-79
5.4
2024-05-02 CVE-2024-3308 Cross-site Scripting vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget's attributes in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping.
network
low complexity
hasthemes CWE-79
5.4
2024-04-24 CVE-2024-32782 Unspecified vulnerability in Hasthemes HT Mega
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HasThemes HT Mega.This issue affects HT Mega: from n/a through 2.4.7.
network
low complexity
hasthemes
6.5
2024-04-09 CVE-2024-1974 Path Traversal vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function.
network
low complexity
hasthemes CWE-22
6.5
2024-03-27 CVE-2024-30182 Unspecified vulnerability in Hasthemes HT Mega
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega allows Stored XSS.This issue affects HT Mega: from n/a through 2.4.3.
network
low complexity
hasthemes
5.4
2024-03-12 CVE-2024-1397 Cross-site Scripting vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on the 'titleTag' user supplied attributes.
network
low complexity
hasthemes CWE-79
5.4