SecAlerts
h

hasthemes

Security Risk Profile

43
/100
medium

Security Risk Score

Comprehensive risk assessment based on 97 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from May 5, 2021 to present

97
Total CVEs
23
Critical+High
0
Exploited
5
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
5
Critical/High
Risk Level
43/100
medium

Severity Distribution

Critical
6
High
17
Medium
74
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
33

Age Distribution

Common Weaknesses (CWE)

1
XSS
46
2
CSRF
28
3
Path Traversal
5
4
SSRF
2
5
Infoleak
2

Most Affected Products

1. HasThemes Ht Mega Wordpress30
2. HasThemes Shoplentor Wordpress19
3. HT Mega Absolute Addons For Elementor17
4. ShopLentor ShopLentor6
5. HT Mega – Absolute Addons For Elementor5

Recent Vulnerabilities

See more →
CVE-2025-68533
CVSS 6.5medium

WordPress WC Builder plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability

Dec 24, 2025🔧 No Patch
CVE-2025-64271
CVSS 6.5medium

WordPress WP Plugin Manager plugin <= 1.4.7 - Cross Site Request Forgery (CSRF) vulnerability

Nov 13, 2025🔧 No Patch
CVE-2025-12493
CVSS 9.8critical

ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template'

Nov 4, 2025🔧 No Patch
CVE-2025-11823
CVSS 6.4medium

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Oct 25, 2025🔧 No Patch
CVE-2025-58990
CVSS 6.5medium

WordPress ShopLentor Plugin <= 3.2.0 - Cross Site Scripting (XSS) Vulnerability

Sep 9, 2025
CVE-2025-8068
CVSS 4.3EPSS 0%medium

HT Mega – Absolute Addons For Elementor <= 2.9.1 - Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions

Jul 31, 2025🔧 No Patch
CVE-2025-8401
CVSS 4.3EPSS 0%medium

HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Sensitive Information Exposure

Jul 31, 2025🔧 No Patch
CVE-2025-8151
CVSS 4.3EPSS 0%medium

HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File Actions

Jul 31, 2025🔧 No Patch
CVE-2025-7340
CVSS 9.8EPSS 0%critical

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload

Jul 15, 2025🔧 No Patch
CVE-2025-7360
CVSS 9.8EPSS 0%critical

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Directory Traversal to Arbitrary File Move

Jul 15, 2025🔧 No Patch

Monitor hasthemes in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

hasthemes Security Vulnerabilities & Risk Score | 97 CVEs | SecAlerts - SecAlerts