CSRF Vulnerability in HasThemes HT Mega - Absolute Addons For Elementor
CVE-2023-51529

8.8HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
29 February 2024

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the HasThemes HT Mega – Absolute Addons for Elementor plugin. This weakness allows an attacker to induce users to execute unwanted actions on a web application in which they are authenticated. If exploited, this vulnerability could enable unauthorized changes or actions that compromise user data integrity. The vulnerability affects versions of the HT Mega plugin before version 2.3.3, making it critical for users to ensure they are updated to the latest version to mitigate potential risks.

Affected Version(s)

HT Mega – Absolute Addons For Elementor <= 2.3.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brandon Roldan (Patchstack Alliance)
.