CVE-2025-8401: HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Sensitive Information Exposure
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'getpostdata' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including the content of private, password-protected, and draft posts and pages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8401?
CVE-2025-8401 is classified as a high severity vulnerability due to its potential for sensitive information exposure.
How do I fix CVE-2025-8401?
To fix CVE-2025-8401, you should update the HT Mega – Absolute Addons For Elementor plugin to version 2.9.2 or later.
Who is affected by CVE-2025-8401?
CVE-2025-8401 affects users of the HT Mega – Absolute Addons For Elementor plugin in all versions up to and including 2.9.1.
What type of vulnerability is CVE-2025-8401?
CVE-2025-8401 is a Sensitive Information Exposure vulnerability that allows authenticated attackers to access sensitive data.
What access level is needed to exploit CVE-2025-8401?
To exploit CVE-2025-8401, an attacker must have at least Author-level access to the WordPress site.