CVE-2024-1974

HIGH

HT Mega - Absolute Addons For Elementor <2.4.6 - Path Traversal

Title source: llm
STIX 2.1

Description

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to read the contents of arbitrary files on the server, which can contain sensitive information.

Scores

CVSS v3 8.8
EPSS 0.0121
EPSS Percentile 64.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
devitemsllc/HT Mega Addons for Elementor – Elementor Widgets & Template Builder < 2.4.6
hasthemes/ht_mega < 2.4.7
Published Apr 09, 2024
Tracked Since Feb 18, 2026