CVE-2025-8151: HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File Actions
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9.1 via the 'saveblockcss' function. This makes it possible for authenticated attackers, with Author-level access and above, to create CSS files in any directory, and delete CSS files in any directory in a Windows environment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8151?
CVE-2025-8151 is classified as a high severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2025-8151?
To fix CVE-2025-8151, update the HT Mega – Absolute Addons For Elementor plugin to version 2.9.2 or later.
Who is affected by CVE-2025-8151?
Authenticated users with Author-level access and higher are primarily affected by CVE-2025-8151.
What is the nature of the vulnerability in CVE-2025-8151?
CVE-2025-8151 is a Path Traversal vulnerability that allows attackers to access restricted server files.
Which versions of the HT Mega plugin are vulnerable to CVE-2025-8151?
All versions up to and including 2.9.1 of the HT Mega – Absolute Addons For Elementor plugin are vulnerable to CVE-2025-8151.