First published: Thu May 02 2024(Updated: )
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_products function. This makes it possible for unauthenticatied attackers to extract sensitive data including the previous 7 days of order data including products and customer PII.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
HT Mega - Absolute Addons for Elementor Page Builder | <=2.4.6 | |
WordPress HT Mega | <2.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6214 is classified as a critical vulnerability due to the potential for unauthenticated attackers to access sensitive information.
To mitigate CVE-2023-6214, update the HT Mega – Absolute Addons For Elementor plugin to version 2.4.7 or later.
CVE-2023-6214 affects all versions of the HT Mega – Absolute Addons For Elementor plugin up to and including 2.4.6.
CVE-2023-6214 is categorized as a Sensitive Information Exposure vulnerability.
CVE-2023-6214 allows unauthenticated attackers to extract sensitive data including purchase history.