๐Ÿ” CVE Alert

CVE-2026-15385

UNKNOWN 0.0

RT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; its only gate is a nonce that any logged-in user can read from a standard admin page. A subscriber-level user can therefore enable the mega menu on a site menu and store a menu-item style value that is rendered, without output escaping, into a style attribute on the public navigation. By breaking out of that attribute the user persists a JavaScript event handler that executes for every visitor who hovers the navigation, including administrators, leading to session/site takeover.

Vendor unknown
Product rt mega menu
Published Aug 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown rt mega menu

Be the first to know when new unknown vulnerabilities affecting unknown rt mega menu are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / RT Mega Menu
0 < 1.5.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/b13b19c6-b6e1-45eb-95f3-ac334bda8b84/

Credits

Shivamani Vastrala WPScan