Input validation vulnerability in HT Mega – Absolute Addons For Elementor 3.0.0

A popular plugin for WordPress, called HT Mega – Absolute Addons For Elementor, has a security vulnerability that allows malicious code to be injected into websites. This happens when the plugin’s Gutenberg blocks are used and the user inputs HTML tag names that are not properly checked. Even though some blocks try to sanitize the code, it can still be bypassed using certain techniques. This means that attackers with contributor level access or higher can inject harmful scripts into pages that will run whenever someone visits those pages.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.