CVE-2024-4875: HT Mega – Absolute Addons For Elementor <= 2.5.2 - Missing Authorization to Options Update
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'ajaxdismiss' function in versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update options such as userscanregister, which can lead to unauthorized user registration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: HT Mega – Absolute Addons For Elementorto a version that resolves this vulnerability.Fixed in 2.5.2 - Configuration
Update the plugin so the ajax_dismiss AJAX handler performs a proper WordPress capability check before processing option updates (the vulnerability is in versions up to and including 2.5.2).
HT Mega – Absolute Addons For Elementor (WordPress plugin) ajax_dismiss capability check = Require appropriate capability for the ajax_dismiss handler (deny requests from subscribers)
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4875?
CVE-2024-4875 is considered a medium severity vulnerability due to the potential for unauthorized data modification.
How do I fix CVE-2024-4875?
To fix CVE-2024-4875, update the HT Mega – Absolute Addons For Elementor plugin to version 2.5.3 or higher.
What versions of the HT Mega – Absolute Addons For Elementor are affected by CVE-2024-4875?
CVE-2024-4875 affects all versions up to and including 2.5.2 of the HT Mega – Absolute Addons For Elementor plugin.
What type of attack is possible due to CVE-2024-4875?
CVE-2024-4875 allows authenticated attackers to modify or potentially loss data through unauthorized actions.
Who is the vendor responsible for CVE-2024-4875?
The vendor responsible for CVE-2024-4875 is HasThemes, which developed the HT Mega – Absolute Addons For Elementor plugin.