SecAlerts
h

ht

Security Risk Profile

44
/100
medium

Security Risk Score

Comprehensive risk assessment based on 11 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 13, 2024 to present

11
Total CVEs
3
Critical+High
0
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
44/100
medium

Severity Distribution

Critical
3
High
0
Medium
8
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
XSS
5
2
Input Validation
1
3
Malicious File Upload
1
4
Path Traversal
1

Most Affected Products

1. HT Mega – Absolute Addons For Elementor6
2. HasThemes Ht Mega Wordpress5
3. HasThemes Download Contact Form 7 Widget For Elementor Page Builder \& Gutenberg Blocks Wordpress3
4. HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder2
5. HT Contact Form Widget1

Recent Vulnerabilities

See more →
CVE-2025-13141
CVSS 6.4medium

HT Mega – Absolute Addons For Elementor <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tag Attribute Injection

Nov 21, 2025🔧 No Patch
CVE-2025-8068
CVSS 4.3EPSS 0%medium

HT Mega – Absolute Addons For Elementor <= 2.9.1 - Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions

Jul 31, 2025🔧 No Patch
CVE-2025-7340
CVSS 9.8EPSS 0%critical

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload

Jul 15, 2025🔧 No Patch
CVE-2025-7360
CVSS 9.8EPSS 0%critical

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Directory Traversal to Arbitrary File Move

Jul 15, 2025🔧 No Patch
CVE-2025-7341
CVSS 9.8EPSS 0%critical

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Deletion

Jul 15, 2025🔧 No Patch
CVE-2025-2779
CVSS 6.5medium

Insert Headers and Footers Code – HT Script <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update

Apr 2, 2025🔧 No Patch
CVE-2024-12597
CVSS 6.4medium

HT Mega <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner_css

Feb 4, 2025
CVE-2024-5215
CVSS 6.4EPSS 0%medium

HT Mega – Absolute Addons For Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

Jun 26, 2024🔧 No Patch
CVE-2024-3989
CVSS 6.4EPSS 0%medium

HT Mega – Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Justify

May 9, 2024🔧 No Patch
CVE-2024-2085
CVSS 6.4medium

HT Mega – Absolute Addons For Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size'

May 2, 2024

Monitor ht in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

ht Security Vulnerabilities & Risk Score | 11 CVEs | SecAlerts - SecAlerts