Impact
The HT Mega Addons for Elementor plugin is vulnerable to stored cross‑site scripting through its Data Table ‘display_options’ setting, which fails to sanitize and escape user input. An authenticated user with contributor or higher privileges can inject JavaScript that will run whenever any user loads a page using the affected Data Table. This can lead to phishing, defacement, session hijacking, cookie theft, and other malicious activities that undermine confidentiality and integrity for all site visitors.
Affected Systems
The flaw is present in all releases of HT Mega Addons for Elementor – Elementor Widgets & Template Builder up to and including version 3.1.1, manufactured by devitemsllc. Any WordPress site that has one of these versions installed and grants contributor‑level or greater access to the plugin configuration is affected.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate to high risk, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is not available, suggesting limited publicly known exploitation data. Attackers need authenticated access, but given that contributor rights are commonly granted to content editors, the attack vector is reasonably attainable. Once stored, the malicious payload will affect every visitor to the pages containing the compromised Data Table, making the exploitation considerably impactful.
OpenCVE Enrichment