PT-2026-95223 · WordPress · Rt Mega Menu
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg versions prior to 1.5.3
Description
Insufficient input sanitization and output escaping allow authenticated attackers with contributor-level access and above to perform Stored Cross-Site Scripting. Attackers can inject arbitrary web scripts via the
pointer menu item block attribute. The payload bypasses wp kses post filtering—a function used to sanitize post content—because it contains no HTML tags and remains intact within the block comment's JSON attributes, reaching the walker unescaped during rendering.Recommendations
Update RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg to version 1.5.3 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rt Mega Menu