CVE-2023-6214: HT Mega – Absolute Addons For Elementor <= 2.4.6 - Sensitive Information Exposure via purchased_products
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchasedproducts function. This makes it possible for unauthenticatied attackers to extract sensitive data including the previous 7 days of order data including products and customer PII.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6214?
CVE-2023-6214 is classified as a critical vulnerability due to the potential for unauthenticated attackers to access sensitive information.
How do I fix CVE-2023-6214?
To mitigate CVE-2023-6214, update the HT Mega – Absolute Addons For Elementor plugin to version 2.4.7 or later.
Who is affected by CVE-2023-6214?
CVE-2023-6214 affects all versions of the HT Mega – Absolute Addons For Elementor plugin up to and including 2.4.6.
What type of vulnerability is CVE-2023-6214?
CVE-2023-6214 is categorized as a Sensitive Information Exposure vulnerability.
What data is exposed in CVE-2023-6214?
CVE-2023-6214 allows unauthenticated attackers to extract sensitive data including purchase history.