The HT Mega plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.2.0. This is due to missing validation of the reg_role parameter on the htmega_ajax_register function. This makes it possible for unauthenticated attackers to create administrator accounts.
id: CVE-2023-37999
info:
name: HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authori
...