CVE-2023-37999

CRITICAL EXPLOITED NUCLEI

Hasthemes HT Mega < 2.2.1 - Improper Privilege Management

Title source: rule

Description

Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.

Nuclei Templates (1)

HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege Escalation
CRITICALVERIFIEDby daffainfo

Scores

CVSS v3 9.8
EPSS 0.5671
EPSS Percentile 98.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-07-14
CWE
CWE-269
Status published
Products (1)
hasthemes/ht_mega < 2.2.1
Published May 17, 2024
Tracked Since Feb 18, 2026