PT-2024-33201 · WordPress · Ht Mega – Absolute Addons For Elementor

1337_Wannabe

+1

·

Published

2024-05-21

·

Updated

2024-05-21

·

CVE-2024-4875

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions HT Mega – Absolute Addons For Elementor plugin for WordPress versions up to, and including, 2.5.2
Description The issue is related to a missing capability check on the ajax dismiss function, allowing authenticated attackers with subscriber-level permissions and above to update options such as users can register. This can lead to unauthorized user registration.
Recommendations For versions up to, and including, 2.5.2, consider disabling the ajax dismiss function until a patch is available to prevent unauthorized modification of data. Restrict access to options such as users can register to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-4875

Affected Products

Ht Mega – Absolute Addons For Elementor