📦 Ht Mega

by Hasthemes

🔍 What is Ht Mega?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-37999

CRITICAL CVSS 9.8 May 17, 2024

This vulnerability allows unauthenticated attackers to escalate privileges in the HT Mega WordPress plugin. Attackers can gain administrative access to affected WordPress sites without requiring any c...

CVE-2024-12599

HIGH CVSS 7.2 Feb 11, 2025

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using the HT Mega plugin's Countdown widget. The scripts are stor...

CVE-2023-6214

HIGH CVSS 7.5 May 2, 2024

The HT Mega plugin for WordPress exposes sensitive order data including customer PII through an unauthenticated API endpoint. This affects all WordPress sites using HT Mega plugin versions up to 2.4.6...

CVE-2024-1974

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in the HT Mega plugin for WordPress allows authenticated attackers with contributor-level access or higher to perform directory traversal attacks. They can read arbitrary files on t...

CVE-2023-50901

HIGH CVSS 7.1 Dec 29, 2023

This vulnerability allows attackers to inject malicious scripts into web pages generated by the HT Mega plugin for WordPress Elementor. When users visit a specially crafted URL, the script executes in...

CVE-2025-8401

MEDIUM CVSS 4.3 Jul 31, 2025

The HT Mega plugin for WordPress has an information disclosure vulnerability that allows authenticated users with Author-level permissions or higher to access private, password-protected, and draft co...

CVE-2025-8068

MEDIUM CVSS 4.3 Jul 31, 2025

This vulnerability in the HT Mega WordPress plugin allows authenticated users with Contributor-level access or higher to delete arbitrary files and move posts/pages/templates to trash due to improper ...

CVE-2025-1802

MEDIUM CVSS 6.4 Mar 20, 2025

This stored XSS vulnerability in the HT Mega WordPress plugin allows authenticated attackers with Contributor access or higher to inject malicious scripts into website pages. When users visit compromi...

CVE-2025-1261

MEDIUM CVSS 6.4 Mar 8, 2025

This vulnerability allows authenticated attackers with contributor-level access or higher to inject malicious scripts into WordPress pages using the HT Mega plugin's Countdown widget. The scripts exec...

CVE-2024-8910

MEDIUM CVSS 4.3 Sep 25, 2024

The HT Mega plugin for WordPress exposes sensitive template data through a vulnerability in the accordion widget. Authenticated attackers with Contributor-level access or higher can extract private, p...

CVE-2024-38706

MEDIUM CVSS 6.5 Jul 12, 2024

This path traversal vulnerability in the HT Mega WordPress plugin allows attackers to access files outside the intended directory by manipulating file paths. It affects all versions up to 2.5.7 of the...

CVE-2024-5173

MEDIUM CVSS 6.4 Jun 26, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using the HT Mega plugin's Video player widget. The scripts execu...

CVE-2024-3990

MEDIUM CVSS 6.4 May 14, 2024

This stored XSS vulnerability in the HT Mega WordPress plugin allows authenticated attackers with contributor-level access or higher to inject malicious scripts into web pages. The scripts execute whe...

CVE-2024-3307

MEDIUM CVSS 6.4 May 2, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using the HT Mega plugin's Countdown widget. The scripts are stor...

CVE-2024-2085

MEDIUM CVSS 6.4 May 2, 2024

This vulnerability allows authenticated WordPress users with contributor-level permissions or higher to inject malicious scripts into web pages using the HT Mega plugin's widgets. The scripts execute ...