CVE-2026-4106
Description
The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and country) of customers who placed orders in the last 7 days
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The HT Mega Addons for Elementor plugin before 3.0.7 exposes an unauthenticated AJAX endpoint that leaks PII of recent customers.
Vulnerability
Details
The HT Mega Addons for Elementor WordPress plugin, versions prior to 3.0.7, contains an unauthenticated AJAX action that returns personally identifiable information (PII) of customers who placed orders in the last 7 days. The exposed data includes full name, city, state, and country [1]. This is a sensitive data disclosure vulnerability that does not require any authentication to exploit.
Exploitation
An attacker can trigger the vulnerable AJAX endpoint without any authentication or special privileges. The endpoint is accessible to any visitor to the site, allowing them to retrieve the PII of recent customers simply by sending a crafted request [1]. No prior knowledge or access is needed.
Impact
Successful exploitation allows an attacker to obtain the full names and location details (city, state, country) of customers who have placed orders recently. This information can be used for targeted phishing campaigns, social engineering, or other malicious activities that rely on personal data [1].
Mitigation
The vulnerability has been fixed in version 3.0.7 of the HT Mega Addons plugin. Users are strongly advised to update to the latest version immediately. No workaround is available [1].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (April 20, 2026 to April 26, 2026)Wordfence Blog · Apr 30, 2026