Impact
The RT Mega Menu WordPress plugin is vulnerable to stored XSS through the ‘pointer_menu_item’ block attribute. Input that contains no HTML tags is not sanitized by wp_kses_post and therefore passes unchanged into the block comment JSON. When the menu is rendered, the attribute value is output unescaped, allowing an authenticated contributor or higher to embed malicious JavaScript that runs in users’ browsers when the affected menu page is viewed. This can lead to credential theft, session hijacking, defacement or arbitrary code execution within the context of a victim’s site.
Affected Systems
Any WordPress installation that has the RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin installed in version 1.5.2 or older. The vulnerability is tied to the plugin’s block rendering logic in files such as build/render.php and rtmega-nav-walker.php, and affects all users who can edit or create menu items through the WordPress editor.
Risk and Exploitability
The CVSS score of 6.4 reflects moderate severity, and an EPSS of less than 1% indicates a low likelihood of widespread exploitation at present. Because the vulnerability requires contributor-level access, it is limited to sites where attackers can gain such permissions, for example through compromised credentials or weak role management. The lack of listing in the CISA KEV catalog suggests there is no known large‑scale exploitation. Nevertheless, the impact of XSS can be considerable, especially if attackers leverage it to target site visitors or to compromise privileged WordPress accounts.
OpenCVE Enrichment