Impact
The RT Mega Menu WordPress plugin stores user‑supplied data from the 'css[left]' parameter in menu markup without proper sanitization. When a user with Subscriber or higher access submits malicious input to the rtmega_update_menu_options AJAX action, the script is persisted and will run in the browsers of any visitor who loads a page containing the affected menu. This allows the attacker to perform client‑side attacks; based on the description, it is inferred that such payloads could be used for phishing, session hijacking, or defacement.
Affected Systems
The flaw exists in the RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin distributed by themewant. Versions up to and including 1.5.1 are impacted. All WordPress sites that support menu editing by Subscriber or higher roles may be vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4 and an EPSS rating below 1%, and it does not appear in the CISA KEV catalog, indicating limited exploitation likelihood. An attacker must first authenticate to the WordPress admin interface and have permission to the rtmega_update_menu_options AJAX request; after injection, the malicious script is stored permanently and will affect all subsequent visitors who load the compromised menu.
OpenCVE Enrichment