The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_products function. This makes it possible for unauthenticatied attackers to extract sensitive data including the previous 7 days of order data including products and customer PII.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Jan 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hasthemes
Hasthemes ht Mega |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:hasthemes:ht_mega:*:*:*:*:free:wordpress:*:* | |
Vendors & Products |
Hasthemes
Hasthemes ht Mega |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-02T08:21:18.088Z
Reserved: 2023-11-20T15:41:57.353Z
Link: CVE-2023-6214

Updated: 2024-08-02T08:21:18.088Z

Status : Analyzed
Published: 2024-05-02T17:15:07.970
Modified: 2025-01-28T19:28:35.700
Link: CVE-2023-6214

No data.