Impact
The HT Mega – Absolute Addons For Elementor plugin contains a flaw in the get_post_data function that allows an attacker with author or higher privileges to retrieve the full content of private, password‑protected, and draft posts and pages. This results in the disclosure of sensitive information that is intended to remain hidden from unauthenticated users. The weakness is an improper access control issue, classified as CWE‑285, where restricted data is accessible to users who should not have such visibility.
Affected Systems
The vulnerability affects the devitemsllc HT Mega Addons for Elementor plugin for WordPress, for any version up to and including 2.9.1. Sites that have installed 2.9.1 or an earlier version are at risk. No other versions are currently listed as affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk level, and the EPSS figure of less than 1% shows that the likelihood of exploitation is very low in the wild. The vulnerability is not yet part of CISA’s KEV catalog. Since the attack requires an authenticated author‑level account, the threat is largely internal; it would be unlikely to succeed from an external source without first compromising credentials.
OpenCVE Enrichment
EUVD