Record summary

CVE-2023-37999 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 14, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 30, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

HT Mega

Browse HasThemes / HT Megaht-mega-for-elementor

Default status: unaffected

CVE ListThrough 2.2.0affected
VulnCheckVersion data not supplied

ht_mega_-_absolute_addons_for_elementor_page_builder

Browse hasthemes / ht_mega_-_absolute_addons_for_elementor_page_builder

Default status: unaffected

CVE ListThrough 2.2.0affected

Nuclei templates

1
ProjectDiscoveryCRITICALHT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege EscalationCVSS 9.8

The HT Mega plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.2.0. This is due to missing validation of the reg_role parameter on the htmega_ajax_register function. This makes it possible for unauthenticated attackers to create administrator accounts.

Impact

Attackers can escalate privileges, gaining unauthorized access to restricted functionalities or data.

Remediation

Update to the latest version of HT Mega to address the privilege management issue.

WeaknessesCWE-269
Authorsdaffainfo
Template tagscvecve2023wordpresswpwp-pluginhasthemesht_megavkevht-mega-for-elementor
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:hasthemes:ht_mega:*:*:*:*:free:wordpress:*:*

Source: ProjectDiscovery

References

2