CVE-2025-8068

HT Mega – Absolute Addons For Elementor <= 2.9.1 - Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajax_trash_templates' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary attachment files, and move arbitrary posts, pages, and templates to the Trash.


We have discovered 7,600 live websites that are affected by CVE-2025-8068.

Run a Free Instant Scan




Affected Software

Product  Ht Mega For Elementor
Category Wordpress Plugins
Vulnerable Domains7,600 live websites (47% of Ht Mega For Elementor install base)
Vulnerable Versions
  • from 0 through 2.9.1
Vulnerable Versions Count157 versions ( 94% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Jul 31, 2025
  • Updated - Jul 31, 2025

Credits

  • wesley (finder)

Website Distribution by Country

Number of websites using CVE-2025-8068
United States1,500 websites



Germany723 websites
France548 websites
Brazil479 websites
India293 websites
Italy291 websites
GB280 websites
Poland253 websites
Russia209 websites
Netherlands203 websites

Website Distribution by TLD

Number of websites using CVE-2025-8068
.com2,786 websites
.com.br413 websites
.de374 websites
.org277 websites
.fr242 websites
.it197 websites
.pl195 websites
.nl190 websites
.ru170 websites
.co.uk143 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-8068

Top websites that are affected by CVE-2025-8068. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.com United States**,***
*****.es Spain**,***
****************.org United States**,***
*******.it Italy**,***
**.*********.***.ph Philippines**,***
****.***.pl Poland***,***
****.**.za South Africa***,***
****.de Germany***,***
********.com United States***,***
*********.org United States***,***
See full domain list

FAQ

CVE-2025-8068 is Incorrect Authorization in Ht Mega For Elementor
A total of 7,600 websites have been identified as vulnerable to CVE-2025-8068, based on global website indexing conducted by WebTechSurvey.
The Ht Mega For Elementor is affected by the CVE-2025-8068 vulnerability.
Ht Mega For Elementor versions up to and including 2.9.1 are vulnerable to CVE-2025-8068.