VYPR

RT Mega Menu

by WordPress

CVEs (5)

  • CVE-2026-15650MedSep 18, 2026
    risk 0.42cvss 6.4epss 0.00

    The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-14855MedSep 18, 2026
    risk 0.42cvss 6.4epss 0.00

    The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-15385MedAug 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; its only gate is a nonce that any logged-in user can read from a standard admin page. A subscriber-level user can…

  • CVE-2026-65433MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.

  • CVE-2026-59559MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.