The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render function in includes/widgets/htmega_accordion.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
We have discovered 7,397 live websites that are affected by CVE-2024-8910.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 7,397 live websites (42.27% of Ht Mega For Elementor install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 134 versions ( 87.01% of all versions) |
![]() | 2,053 websites |
![]() | 955 websites |
![]() | 527 websites |
![]() | 337 websites |
![]() | 319 websites |
![]() | 262 websites |
![]() | 222 websites |
![]() | 221 websites |
![]() | 140 websites |
![]() | 130 websites |
.com | 2,721 websites |
.com.br | 459 websites |
.de | 386 websites |
.org | 271 websites |
.pl | 214 websites |
.fr | 201 websites |
.ru | 179 websites |
.nl | 148 websites |
.net | 133 websites |
.co.uk | 125 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.org | ![]() | **,*** | |
*****.es | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*******.org | ![]() | **,*** | |
*******.it | ![]() | **,*** | |
****.***.pl | ![]() | ***,*** | |
****.**.za | ![]() | ***,*** | |
***.***.br | ![]() | ***,*** | |
****.de | ![]() | ***,*** | |
********.com | ![]() | ***,*** |
FAQ