Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection.

This issue affects WP Mega Menu: from n/a through 1.4.2.
Published: 2026-09-16
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Blind SQL Injection
Action: Apply Patch
AI Analysis

Impact

The vulnerability in Themeum WP Mega Menu allows attackers to inject SQL commands through unsanitized input fields, leading to blind SQL injection. Because the plugin fails to properly neutralize special elements, an attacker can deduce database contents or modify data without direct error messages. This weakness grants unauthorized read or modification of the database, potentially compromising sensitive information stored in the WordPress site.

Affected Systems

WordPress users running the WP Mega Menu plugin version 1.4.2 or earlier are impacted. The plugin, provided by Themeum, is available for WordPress sites that have installed or updated the plugin within that version range. The vulnerability applies from the earliest release through 1.4.2, and patching to a later version beyond 1.4.2 removes the issue.

Risk and Exploitability

The CVSS score of 7.6 indicates serious severity. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to trigger the plugin’s input fields, which may be accessible to authenticated users or public users depending on the plugin configuration, to execute the injection. Given the blind nature of the attack, exploitation requires iterative querying and may involve column enumeration or time delays. If successful, the attacker could extract or alter database records, leading to data loss, exposure, or site compromise.

Generated by OpenCVE AI on September 18, 2026 at 06:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Themeum WP Mega Menu to a version newer than 1.4.2, if available, to ensure the SQL injection flaw is fixed.
  • If an immediate upgrade is not possible, temporarily disable or remove the WP Mega Menu plugin until a patch can be applied.
  • Restrict user access to any configuration or input areas of the plugin and enforce strict input validation to limit the potential for injection.

Generated by OpenCVE AI on September 18, 2026 at 06:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Themehunk
Themehunk mega Menu
Wordpress
Wordpress wordpress
Vendors & Products Themehunk
Themehunk mega Menu
Wordpress
Wordpress wordpress

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.
Title WordPress WP Mega Menu plugin <= 1.4.2 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Themehunk Mega Menu
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-16T15:52:52.488Z

Reserved: 2026-09-16T11:21:22.330Z

Link: CVE-2026-92465

cve-icon Vulnrichment

Updated: 2026-09-16T15:52:48.475Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T12:17:08.073

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-92465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')