HT Mega < 3.0.7 – Unauthenticated PII Disclosure
Summary
| CVE | CVE-2026-4106 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-23 07:16:41 UTC |
| Updated | 2026-04-23 07:16:41 UTC |
| Description | The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and country) of customers who placed orders in the last 7 days |
Risk And Classification
Problem Types: CWE-200 Information Exposure
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | HT Mega Addons For Elementor | affected 3.0.7 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/9477ead2-3990-4aae-8e66-09ee2f4daa3e | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Chiao-Lin Yu (Steven Meow) (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.