Description

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_products function. This makes it possible for unauthenticatied attackers to extract sensitive data including the previous 7 days of order data including products and customer PII.

INFO

Published Date :

2024-05-02T16:52:07.346Z

Last Modified :

2026-04-08T16:53:13.788Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2023-6214 vulnerability.

Vendors Products
Hasthemes
  • Ht Mega

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact