VYPR

Clever Mega Menu for Visual Composer

by WordPress

CVEs (1)

  • CVE-2026-11872Aug 2, 2026
    risk 0.00cvss epss 0.00

    The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings…