WordPress Plugin Vulnerabilities

HT Mega < 2.9.2 - Author+ Sensitive Information Exposure

Description

The plugin is vulnerable to Sensitive Information Exposure via the 'get_post_data' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including the content of private, password-protected, and draft posts and pages.

Affects Plugins

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
wesley (wcraft)
Verified
No

Timeline

Publicly Published
2025-07-30 (about 10 months ago)
Added
2025-07-31 (about 10 months ago)
Last Updated
2025-07-31 (about 10 months ago)

Other