PT-2024-14899 · WordPress · Ht Mega – Absolute Addons For Elementor

Francesco Carlucci

·

Published

2024-05-02

·

Updated

2024-05-02

·

CVE-2023-6214

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HT Mega – Absolute Addons For Elementor plugin for WordPress versions up to, and including, 2.4.6
Description The issue allows unauthorized attackers to extract sensitive data, including the previous 7 days of order data, products, and customer personally identifiable information (PII), via the purchased products function.
Recommendations For versions up to, and including, 2.4.6, consider disabling the purchased products function as a temporary workaround until a patch is available. Restrict access to sensitive data to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-6214

Affected Products

Ht Mega – Absolute Addons For Elementor