Description
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajax_trash_templates' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary attachment files, and move arbitrary posts, pages, and templates to the Trash.
Problem types
CWE-863 Incorrect Authorization
Product status
Any version
Timeline
| 2025-07-22: | Vendor Notified |
| 2025-07-30: | Disclosed |
Credits
wesley
References
www.wordfence.com/...-572f-4eaa-8e8a-bca9e74fe738?source=cve
plugins.trac.wordpress.org/...nclude/class.theme-builder.php
plugins.trac.wordpress.org/changeset/3336533/