hasthemes CVE Vulnerabilities & Metrics

Focus on hasthemes vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About hasthemes Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with hasthemes. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total hasthemes CVEs: 55
Earliest CVE date: 05 May 2021, 19:15 UTC
Latest CVE date: 04 Feb 2025, 07:15 UTC

Latest CVE reference: CVE-2024-12597

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 23

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): -14.81%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): -14.81%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical hasthemes CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.13

Max CVSS: 3.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 55
4.0-6.9 0
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS hasthemes CVEs

These are the five CVEs with the highest CVSS scores for hasthemes, sorted by severity first and recency.

All CVEs for hasthemes

CVE-2024-12597 hasthemes vulnerability CVSS: 0 04 Feb 2025, 07:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_css' and 'inner_css' parameters in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-49630 hasthemes vulnerability CVSS: 0 20 Oct 2024, 08:15 UTC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HT Plugins WP Education allows Stored XSS.This issue affects WP Education: from n/a through 1.2.8.

CVE-2024-8668 hasthemes vulnerability CVSS: 0 25 Sep 2024, 05:15 UTC

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tooltip and countdown functionality in all versions up to, and including, 2.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-38706 hasthemes vulnerability CVSS: 0 12 Jul 2024, 14:15 UTC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HasThemes HT Mega allows Path Traversal.This issue affects HT Mega: from n/a through 2.5.7.

CVE-2024-5215 hasthemes vulnerability CVSS: 0 26 Jun 2024, 07:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-5173 hasthemes vulnerability CVSS: 0 26 Jun 2024, 02:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video player widget settings in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-35699 hasthemes vulnerability CVSS: 0 08 Jun 2024, 15:15 UTC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes HT Feed allows Stored XSS.This issue affects HT Feed: from n/a through 1.2.8.

CVE-2024-4876 hasthemes vulnerability CVSS: 0 21 May 2024, 11:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popover_header_text’ parameter in versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-4875 hasthemes vulnerability CVSS: 0 21 May 2024, 09:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'ajax_dismiss' function in versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update options such as users_can_register, which can lead to unauthorized user registration.

CVE-2023-37999 hasthemes vulnerability CVSS: 0 17 May 2024, 07:15 UTC

Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.

CVE-2024-3990 hasthemes vulnerability CVSS: 0 14 May 2024, 15:42 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip & Popover Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-3989 hasthemes vulnerability CVSS: 0 14 May 2024, 15:42 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gallery Justify Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-3308 hasthemes vulnerability CVSS: 0 02 May 2024, 17:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget's attributes in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-3307 hasthemes vulnerability CVSS: 0 02 May 2024, 17:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget's attributes in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-2790 hasthemes vulnerability CVSS: 0 02 May 2024, 17:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Accordion widget in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-2085 hasthemes vulnerability CVSS: 0 02 May 2024, 17:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' value in several widgets all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-2084 hasthemes vulnerability CVSS: 0 02 May 2024, 17:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's lightbox widget in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-6214 hasthemes vulnerability CVSS: 0 02 May 2024, 17:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.6 via the purchased_products function. This makes it possible for unauthenticatied attackers to extract sensitive data including the previous 7 days of order data including products and customer PII.

CVE-2024-32782 hasthemes vulnerability CVSS: 0 24 Apr 2024, 08:15 UTC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HasThemes HT Mega.This issue affects HT Mega: from n/a through 2.4.7.

CVE-2024-1974 hasthemes vulnerability CVSS: 0 09 Apr 2024, 19:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2024-30182 hasthemes vulnerability CVSS: 0 27 Mar 2024, 12:15 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega allows Stored XSS.This issue affects HT Mega: from n/a through 2.4.3.

CVE-2024-1421 hasthemes vulnerability CVSS: 0 12 Mar 2024, 23:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the Post Carousel widget in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-1397 hasthemes vulnerability CVSS: 0 12 Mar 2024, 23:15 UTC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on the 'titleTag' user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-51529 hasthemes vulnerability CVSS: 0 29 Feb 2024, 05:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Mega – Absolute Addons For Elementor.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2.3.3.

CVE-2023-51372 hasthemes vulnerability CVSS: 0 29 Dec 2023, 11:15 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HashBar – WordPress Notification Bar allows Stored XSS.This issue affects HashBar – WordPress Notification Bar: from n/a through 1.4.1.

CVE-2023-50901 hasthemes vulnerability CVSS: 0 29 Dec 2023, 11:15 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega – Absolute Addons For Elementor allows Reflected XSS.This issue affects HT Mega – Absolute Addons For Elementor: from n/a through 2.3.8.

CVE-2023-32962 hasthemes vulnerability CVSS: 0 30 Aug 2023, 12:15 UTC

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in HasTheme WishSuite – Wishlist for WooCommerce plugin <= 1.3.4 versions.

CVE-2022-47172 hasthemes vulnerability CVSS: 0 17 Jul 2023, 15:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.6.2 versions.

CVE-2023-23731 hasthemes vulnerability CVSS: 0 11 Jul 2023, 08:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in HasTheme WishSuite plugin <= 1.3.3 versions.

CVE-2023-23803 hasthemes vulnerability CVSS: 0 11 Jul 2023, 07:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes JustTables plugin <= 1.4.9 versions.

CVE-2023-23791 hasthemes vulnerability CVSS: 0 11 Jul 2023, 07:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Menu plugin <= 1.2.1 versions.

CVE-2023-23792 hasthemes vulnerability CVSS: 0 11 Jul 2023, 06:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Swatchly plugin <= 1.2.0 versions.

CVE-2023-23804 hasthemes vulnerability CVSS: 0 10 Jul 2023, 16:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Feed plugin <= 1.2.7 versions.

CVE-2023-23802 hasthemes vulnerability CVSS: 0 15 Jun 2023, 13:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6 versions.

CVE-2023-23801 hasthemes vulnerability CVSS: 0 06 Apr 2023, 13:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6 versions.

CVE-2023-1089 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The Coupon Zen WordPress plugin before 1.0.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-1088 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The WP Plugin Manager WordPress plugin before 1.1.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-1087 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-1086 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The Preview Link Generator WordPress plugin before 1.0.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0505 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The Ever Compare WordPress plugin through 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0504 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The HT Politic WordPress plugin before 2.3.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0503 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0502 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0501 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0500 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0499 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0498 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0497 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0496 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0495 hasthemes vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2022-46798 hasthemes vulnerability CVSS: 0 01 Mar 2023, 15:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change.

CVE-2023-23899 hasthemes vulnerability CVSS: 0 17 Feb 2023, 15:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Extensions For CF7 plugin <= 2.0.8 versions leads to arbitrary plugin activation.

CVE-2022-4650 hasthemes vulnerability CVSS: 0 23 Jan 2023, 15:15 UTC

The HashBar WordPress plugin before 1.3.6 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2021-24262 hasthemes vulnerability CVSS: 3.5 05 May 2021, 19:15 UTC

The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVE-2021-24261 hasthemes vulnerability CVSS: 3.5 05 May 2021, 19:15 UTC

The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.