CVE-2025-54695: WordPress HT Mega Plugin plugin <= 2.9.0 - Broken Access Control Vulnerability
Missing Authorization vulnerability in DevItems HT Mega ht-mega-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HT Mega: from n/a through <= 2.9.0.
Other sources
Missing Authorization vulnerability in HasTech HT Mega allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HT Mega: from n/a through 2.9.0.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54695?
CVE-2025-54695 is classified as a severe Missing Authorization vulnerability.
How do I fix CVE-2025-54695?
To fix CVE-2025-54695, upgrade HasTech HT Mega to the latest version beyond 2.9.0.
What systems are affected by CVE-2025-54695?
CVE-2025-54695 affects all versions of HasTech HT Mega and HT Mega Plugin up to and including 2.9.0.
What can attackers do with CVE-2025-54695?
Attackers can exploit CVE-2025-54695 to bypass access controls and gain unauthorized access to sensitive areas of the application.
Is there a workaround for CVE-2025-54695?
Currently, the only recommended way to mitigate CVE-2025-54695 is to update to a patched version.