Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-6214


The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_products function. This makes it possible for unauthenticatied attackers to extract sensitive data including the previous 7 days of order data including products and customer PII.


Published

2024-05-02T17:15:07.970

Last Modified

2025-01-28T19:28:35.700

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hasthemes ht_mega < 2.4.7 Yes

References