Vulnerabilities > Hasthemes > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-03-12 CVE-2024-1421 Cross-site Scripting vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the Post Carousel widget in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping.
network
low complexity
hasthemes CWE-79
5.4
2023-12-29 CVE-2023-50901 Unspecified vulnerability in Hasthemes HT Mega
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega – Absolute Addons For Elementor allows Reflected XSS.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2.3.8.
network
low complexity
hasthemes
6.1
2023-12-29 CVE-2023-51372 Unspecified vulnerability in Hasthemes Hashbar
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HashBar – WordPress Notification Bar allows Stored XSS.This issue affects HashBar – WordPress Notification Bar: from n/a through 1.4.1.
network
low complexity
hasthemes
4.8
2023-08-30 CVE-2023-32962 Unspecified vulnerability in Hasthemes Wishsuite
Auth.
network
low complexity
hasthemes
4.8
2023-03-27 CVE-2023-0484 Unspecified vulnerability in Hasthemes Contact Form 7 Widget for Elementor Page Builder & Gutenberg Blocks
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
network
low complexity
hasthemes
4.3
2023-03-27 CVE-2023-0495 Unspecified vulnerability in Hasthemes HT Slider for Elementor
The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
network
low complexity
hasthemes
4.3
2023-03-27 CVE-2023-0496 Unspecified vulnerability in Hasthemes HT Event
The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
network
low complexity
hasthemes
4.3
2023-03-27 CVE-2023-0497 Unspecified vulnerability in Hasthemes HT Portfolio
The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
network
low complexity
hasthemes
4.3
2023-03-27 CVE-2023-0498 Cross-Site Request Forgery (CSRF) vulnerability in Hasthemes WP Education
The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
network
low complexity
hasthemes CWE-352
4.3
2023-03-27 CVE-2023-0499 Unspecified vulnerability in Hasthemes Quickswish
The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
network
low complexity
hasthemes
4.3