PT-2026-67073 · WordPress · Rt Mega Menu
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
RT Mega Menu versions prior to 1.5.2
Description
The plugin fails to perform a capability check on the AJAX action used to save mega-menu configuration and per-menu-item settings. The only security measure is a nonce that any logged-in user can access from a standard admin page. Consequently, a user with subscriber-level privileges can enable the mega menu and store a menu-item style value. This value is rendered without output escaping into a style attribute on the public navigation. An attacker can break out of this attribute to persist a JavaScript event handler that executes for any visitor who hovers over the navigation, including administrators, potentially leading to session or site takeover.
Recommendations
Update to version 1.5.2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rt Mega Menu