Vulnerabilities > Hasthemes > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-10-20 | CVE-2024-49630 | Cross-site Scripting vulnerability in Hasthemes WP Education Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HT Plugins WP Education allows Stored XSS.This issue affects WP Education: from n/a through 1.2.8. | 5.4 |
2024-09-25 | CVE-2024-8910 | Unspecified vulnerability in Hasthemes HT Mega The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render function in includes/widgets/htmega_accordion.php. | 4.3 |
2024-09-25 | CVE-2024-8668 | Cross-site Scripting vulnerability in Hasthemes Woolentor - Woocommerce Elementor Addons + Builder The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tooltip and countdown functionality in all versions up to, and including, 2.9.7 due to insufficient input sanitization and output escaping. | 5.4 |
2024-06-08 | CVE-2024-35699 | Cross-site Scripting vulnerability in Hasthemes HT Feed Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes HT Feed allows Stored XSS.This issue affects HT Feed: from n/a through 1.2.8. | 5.4 |
2023-12-29 | CVE-2023-50901 | Cross-site Scripting vulnerability in Hasthemes HT Mega Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega – Absolute Addons For Elementor allows Reflected XSS.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2.3.8. | 6.1 |
2023-12-29 | CVE-2023-51372 | Cross-site Scripting vulnerability in Hasthemes Hashbar Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HashBar – WordPress Notification Bar allows Stored XSS.This issue affects HashBar – WordPress Notification Bar: from n/a through 1.4.1. | 4.8 |
2023-08-30 | CVE-2023-32962 | Cross-site Scripting vulnerability in Hasthemes Wishsuite Auth. | 4.8 |
2023-03-27 | CVE-2023-0484 | Unspecified vulnerability in Hasthemes Contact Form 7 Widget for Elementor Page Builder & Gutenberg Blocks The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | 4.3 |
2023-03-27 | CVE-2023-0495 | Unspecified vulnerability in Hasthemes HT Slider for Elementor The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | 4.3 |
2023-03-27 | CVE-2023-0496 | Unspecified vulnerability in Hasthemes HT Event The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | 4.3 |