The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajax_trash_templates' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary attachment files, and move arbitrary posts, pages, and templates to the Trash.
We have discovered 7,600 live websites that are affected by CVE-2025-8068.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 7,600 live websites (47% of Ht Mega For Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 157 versions ( 94% of all versions) |
| 1,500 websites | |
| 723 websites | |
| 548 websites | |
| 479 websites | |
| 293 websites | |
| 291 websites | |
| 280 websites | |
| 253 websites | |
| 209 websites | |
| 203 websites |
| .com | 2,786 websites |
| .com.br | 413 websites |
| .de | 374 websites |
| .org | 277 websites |
| .fr | 242 websites |
| .it | 197 websites |
| .pl | 195 websites |
| .nl | 190 websites |
| .ru | 170 websites |
| .co.uk | 143 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.com | **,*** | ||
| *****.es | **,*** | ||
| ****************.org | **,*** | ||
| *******.it | **,*** | ||
| **.*********.***.ph | **,*** | ||
| ****.***.pl | ***,*** | ||
| ****.**.za | ***,*** | ||
| ****.de | ***,*** | ||
| ********.com | ***,*** | ||
| *********.org | ***,*** |
FAQ