Impact
The Clever Mega Menu for Visual Composer plugin through version 1.0.1 has an AJAX endpoint that updates navigation menu item metadata without performing a nonce or capability check. An authenticated user, including those with Subscriber level access, can send requests to this endpoint and overwrite menu item content and settings that are rendered on the public site. This flaw typifies an improper authorization weakness (CWE‑284) that allows a lower‑privileged user to change navigation behavior, potentially leading to defacement, phishing links, or other disruptive content changes.
Affected Systems
All installations of the Clever Mega Menu for Visual Composer plugin with a version equal to or lower than 1.0.1. No specific sub‑versions are listed beyond the maximum version.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The vulnerability requires a logged‑in user with Subscriber privileges to execute the malicious AJAX call, making the attack surface limited to sites that expose the endpoint to authenticated users. The EPSS score is under 1%, and the issue is not listed in CISA’s KEV catalog, indicating that widespread exploitation is currently unlikely. However, on sites where many subscriber accounts exist or where the plugin is used in a public or customer‑facing environment, the potential impact of unauthorized navigation modification remains significant. The absence of a nonce or capability verification substantially lowers the effort required for an attacker who has legitimate access.
OpenCVE Enrichment