/Vulnerability Library

HT Mega < 3.0.7 - Sensitive Information Disclosure

CVE-2026-4106
Verified

Description

The HT Mega plugin for WordPress is vulnerable to Sensitive Information Exposure via AJAX actions. This template dynamically extracts the security nonce before exploitation.

Severity

High

CVSS Score

7.5

Exploit Probability

1%

Affected Product

ht-mega-for-elementor

Published Date

April 12, 2026

Template Author

efetr

CVE-2026-4106.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-4106

References

https://wpscan.com/vulnerability/9477ead2-3990-4aae-8e66-09ee2f4daa3e/https://nvd.nist.gov/vuln/detail/CVE-2026-4106