Hasthemes develops a suite of WordPress and WooCommerce plugins and page-builder extensions, including HT Mega, Shoplentor, and Woolentor, that extend Elementor functionality for e-commerce and content creation. The vendor's vulnerability profile centers on web-application input-handling and authorization flaws: cross-site scripting, cross-site request forgery, missing authorization controls, and path-traversal issues that are endemic to plugin ecosystems where third-party code integrates deeply with WordPress's permission model. A meaningful share of the vendor's disclosures reach serious severity. The recurring weakness classes reflect the typical surface of WordPress plugins—form input sanitization, nonce validation, and file-access boundaries—and underscore why plugin security audits are integral to WordPress deployment hardening. Defenders should prioritize this vendor's security updates as part of routine WordPress maintenance and review access controls for sites running multiple Hasthemes extensions; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hasthemes over time
Signals from CVEs in this vendor scope (97 CVEs).
97 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-37999CRITICAL Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0. | May 17, 2024 | 9.8 | 41 | NO | YES |
CVE-2025-12493CRITICAL The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Local File Inclusion in | Nov 4, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-7341CRITICAL The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path | Jul 15, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-7340CRITICAL The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida | Jul 15, 2025 | 9.8 | 30 | NO | NO |
CVE-2023-0232CRITICAL The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection. | Feb 21, 2023 | 9.8 | 30 | NO | NO |
CVE-2025-7360CRITICAL The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path va | Jul 15, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-23801HIGH Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6 versions. | Apr 6, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-23803HIGH Cross-Site Request Forgery (CSRF) vulnerability in HasThemes JustTables plugin <= 1.4.9 versions. | Jul 11, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-23802HIGH Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6 versions. | Jun 15, 2023 | 8.8 | 25 | NO | NO |
CVE-2024-38706HIGH Path Traversal: '.../...//' vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a through <= 2.5.7. | Jul 12, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (97 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hasthemes.
Media articles that mention a CVE ID that affects a product developed by Hasthemes — matched by CVE ID, not by vendor name.