What the vulnerability does
01Description
Insertion of Sensitive Information Into Sent Data vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a through <= 2.4.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information Into Sent Data vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a through <= 2.4.7.
Explanation of Vulnerability in Simple Terms
HT Mega versions up to 2.4.7 expose sensitive information to authenticated users. A logged-in user with low privileges can read data they should not have access to. The vulnerability requires an active user account but no special interaction. Update to a version newer than 2.4.7.
What an attacker can do
Read sensitive information accessible only to higher-privilege users.
Potential impact on your site
Authenticated users can view data intended for administrators or other restricted roles.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities