CVE-2026-4106
HT Mega < 3.0.7 – Unauthenticated PII Disclosure
The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and country) of customers who placed orders in the last 7 days
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
Unknown · HT Mega Addons for Elementorpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/9477ead2-3990-4aae-8e66-09ee2f4daa3e/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →