Input validation vulnerability in HT Mega – Absolute Addons For Elementor 2.3.3

The HT Mega plugin for WordPress is not secure in versions up to 2.3.3. A vulnerability in this plugin, known as Cross-Site Request Forgery, can allow unauthenticated attackers to install and activate plugins without permission. This is because the security measure known as nonce validation is either not included or not working correctly in the /admin/include/template-library.php file. An unauthenticated attacker could potentially trick a website administrator into clicking a malicious link and thus gain access to the site.

Detected in:

HT Mega – Absolute Addons For Elementor fixed vulnerable versions: >= * <= 2.3.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.