SecAlerts
h

ht mega

Security Risk Profile

26
/100
low

Security Risk Score

Comprehensive risk assessment based on 18 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 12, 2024 to present

18
Total CVEs
2
Critical+High
0
Exploited
0
Unpatched

Threat Assessment

Avg CVSS
6.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
26/100
low

Severity Distribution

Critical
0
High
2
Medium
16
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
8

Age Distribution

Common Weaknesses (CWE)

1
XSS
12
2
Infoleak
2
3
Path Traversal
2

Most Affected Products

1. HT Mega Absolute Addons For Elementor17
2. HasThemes Ht Mega Wordpress17
3. HT Mega HT Mega Addons for Elementor1

Recent Vulnerabilities

See more →
CVE-2026-4106
CVSS 5.3medium

HT Mega < 3.0.7 – Unauthenticated PII Disclosure

Apr 23, 2026🔧 No Patch
CVE-2025-8401
CVSS 4.3EPSS 0%medium

HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Sensitive Information Exposure

Jul 31, 2025🔧 No Patch
CVE-2025-8151
CVSS 4.3EPSS 0%medium

HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File Actions

Jul 31, 2025🔧 No Patch
CVE-2025-1802
CVSS 6.4medium

HT Mega – Absolute Addons For Elementor <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

Mar 20, 2025
CVE-2025-1261
CVSS 6.4medium

HT Mega – Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget

Mar 8, 2025
CVE-2024-12599
CVSS 6.4medium

HT Mega – Absolute Addons For Elementor <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

Feb 11, 2025
CVE-2024-5173
CVSS 6.4EPSS 0%medium

HT Mega – Absolute Addons For Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Player Widget Settings

Jun 26, 2024🔧 No Patch
CVE-2024-4876
CVSS 6.4EPSS 0%medium

HT Mega – Absolute Addons For Elementor <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 21, 2024🔧 No Patch
CVE-2024-4875
CVSS 4.3EPSS 0%medium

HT Mega – Absolute Addons For Elementor <= 2.5.2 - Missing Authorization to Options Update

May 21, 2024🔧 No Patch
CVE-2024-3990
CVSS 6.4EPSS 0%medium

HT Mega – Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tooltip & Popover Widget

May 9, 2024

Monitor ht mega in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

ht mega Security Vulnerabilities & Risk Score | 18 CVEs | SecAlerts - SecAlerts