
HT Mega Addons for Elementor – Elementor Widgets & Template Builder Security & Risk Analysis
wordpress.org/plugins/ht-mega-for-elementorElementor addon offering 135+ widgets — Mega Menu, Ready Templates, Page Builder, Slider, Gallery, Post Grid, AI Writer & more.
Is HT Mega Addons for Elementor – Elementor Widgets & Template Builder Safe to Use in 2026?
Mostly Safe
Score 82/100HT Mega Addons for Elementor – Elementor Widgets & Template Builder is generally safe to use. 32 past CVEs were resolved. Keep it updated.
The ht-mega-for-elementor v3.0.6 plugin exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query sanitization (86% prepared) and extensive use of nonces and capability checks (30 and 42 respectively), significant concerns remain. The presence of one AJAX handler without any authentication check represents a direct, exploitable vulnerability.
The taint analysis reveals two high-severity flows, indicating potential for serious security issues, though the specific nature isn't detailed. The history of 32 CVEs, including one critical and three high-severity vulnerabilities, is a major red flag. While there are currently no unpatched CVEs, the sheer volume and historical recurrence of common vulnerability types such as improper authorization, path traversal, and cross-site scripting suggest a pattern of recurring security flaws. The plugin has a large attack surface with 27 entry points, and one being unprotected is a critical oversight. The output escaping at 74% is also a concern, as it leaves room for potential XSS vulnerabilities.
Key Concerns
- AJAX handler without authentication
- 2 high severity taint flows
- 32 total known CVEs
- 1 critical CVE in history
- 3 high CVEs in history
- Common vulnerability types (Improper Auth, Path Traversal, XSS)
- Output escaping at 74%
HT Mega Addons for Elementor – Elementor Widgets & Template Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
32 total CVEs
HT Mega – Absolute Addons For Elementor <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tag Attribute Injection
HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File Actions
HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Sensitive Information Exposure
HT Mega – Absolute Addons For Elementor <= 2.9.1 - Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions
HT Mega <= 2.9.0 - Missing Authorization
HT Mega – Absolute Addons For Elementor <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
HT Mega – Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget
HT Mega – Absolute Addons For Elementor <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
HT Mega <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner_css
HT Mega – Absolute Addons For Elementor <= 2.6.5 - Authenticated (Contributor+) Sensitive Information Exposure via template_id
HT Mega <= 2.5.7 - Authenticated (Contributor+) JSON File Directory Traversal
HT Mega – Absolute Addons For Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
HT Mega – Absolute Addons For Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Player Widget Settings
HT Mega – Absolute Addons For Elementor <= 2.4.5 - Authenticated (Contributor+) Directory Traversal
HT Mega – Absolute Addons For Elementor <= 2.5.2 - Missing Authorization to Options Update
HT Mega – Absolute Addons For Elementor <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
HT Mega – Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Justify
HT Mega – Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tooltip & Popover Widget
HT Mega – Absolute Addons For Elementor <= 2.4.7 - Missing Authorization to Information Exposure
HT Mega – Absolute Addons For Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size'
HT Mega – Absolute Addons For Elementor <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Grid Widget
HT Mega – Absolute Addons For Elementor <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion/FAQ
HT Mega – Absolute Addons For Elementor <= 2.4.6 - Sensitive Information Exposure via purchased_products
HT Mega – Absolute Addons For Elementor <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lightbox Widget
HT Mega – Absolute Addons For Elementor <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
HT Mega <= 2.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
HT Mega <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via titleTag
HT Mega – Absolute Addons For Elementor <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Carousel Widget
HT Mega <= 2.3.3 - Cross-Site Request Forgery via Several Functions
HT Mega – Absolute Addons For Elementor <= 2.3.8 - Reflected Cross-Site Scripting
HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege Escalation
HT Mega - Absolute Addons for Elementor Page Builder <= 1.5.5 - Contributor+ Stored Cross-Site Scripting
HT Mega Addons for Elementor – Elementor Widgets & Template Builder Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
HT Mega Addons for Elementor – Elementor Widgets & Template Builder Attack Surface
AJAX Handlers 27
WordPress Hooks 140
Maintenance & Trust
HT Mega Addons for Elementor – Elementor Widgets & Template Builder Maintenance & Trust
Maintenance Signals
Community Trust
HT Mega Addons for Elementor – Elementor Widgets & Template Builder Alternatives
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Royal Addons for Elementor – Addons and Templates Kit for Elementor
royal-elementor-addons
Elementor templates, Header footer builder, Elementor Post Grid, Woocommerce Grid builder, Slider, Forms, Gallery, Nav menu addons, Elementor widgets.
Unlimited Elements For Elementor
unlimited-elements-for-elementor
Elementor all-in-one addons pack with the best widgets for Elementor, offering 100+ free widgets, templates, and tools to create stunning websites!
HT Mega Addons for Elementor – Elementor Widgets & Template Builder Developer Profile
13 plugins · 179K total installs
How We Detect HT Mega Addons for Elementor – Elementor Widgets & Template Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.