CVE-2025-8068: HT Mega – Absolute Addons For Elementor <= 2.9.1 - Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajaxtrashtemplates' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary attachment files, and move arbitrary posts, pages, and templates to the Trash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8068?
CVE-2025-8068 has a high severity level due to the potential for unauthorized modification and data loss.
How do I fix CVE-2025-8068?
To fix CVE-2025-8068, update the HT Mega – Absolute Addons For Elementor plugin to version 2.9.2 or later.
Who is affected by CVE-2025-8068?
CVE-2025-8068 affects all versions of the HT Mega – Absolute Addons For Elementor plugin up to and including version 2.9.1.
What capabilities are improperly checked in CVE-2025-8068?
CVE-2025-8068 involves an improper capability check on the 'ajax_trash_templates' function.
Can CVE-2025-8068 lead to unauthorized access?
Yes, CVE-2025-8068 can potentially allow attackers to gain unauthorized access to modify templates.