CVE-2023-37999
WordPress HT Mega Absolute Addons for Elementor plugin <= 2.2.0 - Unauthenticated Privilege Escalation vulnerability
Record summary
CVE-2023-37999 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 14, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 30, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through 2.2.0 | affected |
HT MegaBrowse HasThemes / HT Mega | VulnCheck | Version data not supplied | |
ht_mega_-_absolute_addons_for_elementor_page_builderBrowse hasthemes / ht_mega_-_absolute_addons_for_elementor_page_builderDefault status: unaffected | CVE List | Through 2.2.0 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALHT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege EscalationCVSS 9.8
The HT Mega plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.2.0. This is due to missing validation of the reg_role parameter on the htmega_ajax_register function. This makes it possible for unauthenticated attackers to create administrator accounts.
Impact
Attackers can escalate privileges, gaining unauthorized access to restricted functionalities or data.
Remediation
Update to the latest version of HT Mega to address the privilege management issue.
Source: ProjectDiscovery