First published: Wed Mar 27 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega allows Stored XSS.This issue affects HT Mega: from n/a through 2.4.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress HT Mega | <2.4.4 | |
HasThemes HT Mega WordPress | <=2.4.3 | |
HT Mega Absolute Addons For Elementor | <=2.4.3 |
Update to 2.4.4 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-30182 is categorized as a high-risk vulnerability due to its ability to enable stored cross-site scripting (XSS).
To fix CVE-2024-30182, update the HasThemes HT Mega plugin to version 2.4.4 or later, as this release addresses the vulnerability.
CVE-2024-30182 affects all versions of HasThemes HT Mega up to and including version 2.4.3.
CVE-2024-30182 is a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages.
CVE-2024-30182 impacts HasThemes HT Mega and WordPress HT Mega – Absolute Addons For Elementor plugin versions up to 2.4.3.