CSRF Vulnerability in HasThemes HT Mega - Absolute Addons For Elementor
CVE-2023-51529
8.8HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 29 February 2024
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the HasThemes HT Mega – Absolute Addons for Elementor plugin. This weakness allows an attacker to induce users to execute unwanted actions on a web application in which they are authenticated. If exploited, this vulnerability could enable unauthorized changes or actions that compromise user data integrity. The vulnerability affects versions of the HT Mega plugin before version 2.3.3, making it critical for users to ensure they are updated to the latest version to mitigate potential risks.
Affected Version(s)
HT Mega – Absolute Addons For Elementor <= 2.3.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Brandon Roldan (Patchstack Alliance)