Description
The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-09-18
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The RT Mega Menu WordPress plugin stores user‑supplied data from the 'css[left]' parameter in menu markup without proper sanitization. When a user with Subscriber or higher access submits malicious input to the rtmega_update_menu_options AJAX action, the script is persisted and will run in the browsers of any visitor who loads a page containing the affected menu. This allows the attacker to perform client‑side attacks; based on the description, it is inferred that such payloads could be used for phishing, session hijacking, or defacement.

Affected Systems

The flaw exists in the RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin distributed by themewant. Versions up to and including 1.5.1 are impacted. All WordPress sites that support menu editing by Subscriber or higher roles may be vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.4 and an EPSS rating below 1%, and it does not appear in the CISA KEV catalog, indicating limited exploitation likelihood. An attacker must first authenticate to the WordPress admin interface and have permission to the rtmega_update_menu_options AJAX request; after injection, the malicious script is stored permanently and will affect all subsequent visitors who load the compromised menu.

Generated by OpenCVE AI on September 19, 2026 at 20:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the RT Mega Menu plugin to the latest version that contains the fix (i.e., any release beyond 1.5.1).
  • If upgrading is not immediately possible, block or disable the rtmega_update_menu_options AJAX endpoint for users with Subscriber-level or higher capabilities, using .htaccess rules or a security‑plugin firewall rule.
  • Remove any existing menu entries that contain suspicious or malicious JavaScript before disabling the endpoint.

Generated by OpenCVE AI on September 19, 2026 at 20:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Themewant
Themewant rt Mega Menu – Mega Menu Builder For Elementor & Gutenberg
Wordpress
Wordpress wordpress
Vendors & Products Themewant
Themewant rt Mega Menu – Mega Menu Builder For Elementor & Gutenberg
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title RT Mega Menu <= 1.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via rtmega_update_menu_options AJAX Action
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Themewant Rt Mega Menu – Mega Menu Builder For Elementor & Gutenberg
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T14:31:42.657Z

Reserved: 2026-07-06T12:04:45.770Z

Link: CVE-2026-14855

cve-icon Vulnrichment

Updated: 2026-09-18T14:29:38.493Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T03:16:33.040

Modified: 2026-09-18T15:17:05.243

Link: CVE-2026-14855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:00:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')