The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and country) of customers who placed orders in the last 7 days
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small standalone Python exploit PoC for CVE-2026-4106 against the WordPress HT Mega plugin. Structure is minimal: README.md documents the vulnerability and usage, requirements.txt lists requests/urllib3, and exploit.py contains the full scanner/exploit logic. The script supports single-target and mass-scan modes, using a ThreadPoolExecutor for concurrent scanning. Operational flow: it normalizes target URLs, fetches the homepage, fingerprints likely WordPress/HT Mega installations by checking for '/wp-content/' and 'htmega' in the HTML, extracts possible 10-hex-character nonce values via regex, then sends POST requests to /wp-admin/admin-ajax.php across a hardcoded list of HT Mega-related AJAX actions. For each action it tries requests both without a nonce and with nonce/security parameters, using limit=1000 to maximize returned records. It attempts to identify successful disclosure by parsing JSON or matching sensitive field names such as fname, lname, email, buyer, city, phone, price, user_login, and message. When data is found, it writes structured output to exploited_PII.json and a human-readable summary to exploited_summary.txt. The code includes SSL verification bypass, a custom requests adapter lowering TLS security settings for legacy servers, randomized User-Agent rotation, spoofed X-Forwarded-For headers, and broad exception suppression. Overall purpose: unauthenticated bulk harvesting of PII and related content from vulnerable HT Mega AJAX endpoints on WordPress sites.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.