Access violation vulnerability in HT Mega – Absolute Addons For Elementor 2.9.1

The HT Mega plugin for WordPress is at risk of being changed and losing information because it does not properly check for the right permissions. This means that someone who is logged in and has Contributor-level or higher access can delete any attachment files they want, and move any posts, pages, or templates to the Trash.

Detected in:

HT Mega – Absolute Addons For Elementor fixed vulnerable versions: >= * <= 2.9.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.