CVE-2026-4106

The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and country) of customers who placed orders in the last 7 days
Configurations

No configuration.

History

No history.

Information

Published : 2026-04-23 07:16

Updated : 2026-06-17 10:55


NVD link : CVE-2026-4106

Mitre link : CVE-2026-4106

CVE.ORG link : CVE-2026-4106


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor