CVE-2026-4106
HT Mega < 3.0.7 โ Unauthenticated PII Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and country) of customers who placed orders in the last 7 days
| Vendor | unknown |
| Product | ht mega addons for elementor |
| Published | Apr 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown ht mega addons for elementor
Be the first to know when new unknown vulnerabilities affecting unknown ht mega addons for elementor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / HT Mega Addons for Elementor
0 < 3.0.7
References
Credits
Chiao-Lin Yu (Steven Meow) WPScan