Ht Mega
Vendor:
First CVE: May 5, 2021 · Active for 5 years
30
Total CVEs
More Total CVEs than 96% of tracked products
7.5
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ht Mega over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2021
5 years ago
Most Recent CVE
Jul 31, 2025
358 days ago
CVE Severity & Scoring
Ht Mega30 CVEs
87%
10%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network30 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (36.7%)
Unknown0 (0.0%)
Required19 (63.3%)
Privileges Required
Low26 (86.7%)
High0 (0.0%)
None4 (13.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-37999CRITICAL Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0. | May 17, 2024 | 9.8 | 41 | NO | YES |
CVE-2024-38706HIGH Path Traversal: '.../...//' vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a through <= 2.5.7. | Jul 12, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-51529HIGH Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Mega – Absolute Addons For Elementor.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2. | Feb 29, 2024 | 8.8 | 23 | NO | NO |
CVE-2023-6214HIGH The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_produ | May 2, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-8068MEDIUM The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajax_trash_ | Jul 31, 2025 | 4.3 | 21 | NO | NO |
CVE-2024-12599MEDIUM The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including | Feb 11, 2025 | 6.4 | 20 | NO | NO |
CVE-2024-32782MEDIUM Insertion of Sensitive Information Into Sent Data vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a through <= 2.4.7. | Apr 24, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-1974MEDIUM The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This make | Apr 9, 2024 | 6.5 | 19 | NO | NO |
CVE-2025-8151MEDIUM The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9.1 via the 'save_block_css' function. This | Jul 31, 2025 | 4.3 | 18 | NO | NO |
CVE-2025-1802MEDIUM The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text' | Mar 20, 2025 | 5.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (30 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (30 CVEs).
Media Mentions
Signals from CVEs in this product scope (30 CVEs).
Top CNAs Publishing CVEs For Ht Mega
Top CWEs
Versions
No cataloged versions.