HT Mega < 3.0.7 - Sensitive Information Disclosure
CVE-2026-4106
Verified
Description
The HT Mega plugin for WordPress is vulnerable to Sensitive Information Exposure via AJAX actions. This template dynamically extracts the security nonce before exploitation.
Severity
High
CVSS Score
7.5
Exploit Probability
1%
Affected Product
ht-mega-for-elementor
Published Date
April 12, 2026
Template Author
efetr
CVE-2026-4106.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-4106