PT-2026-95223 · WordPress · Rt Mega Menu

·

CVE-2026-15650

·

Published

2026-09-18

·

Updated

2026-09-24

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg versions prior to 1.5.3
Description Insufficient input sanitization and output escaping allow authenticated attackers with contributor-level access and above to perform Stored Cross-Site Scripting. Attackers can inject arbitrary web scripts via the pointer menu item block attribute. The payload bypasses wp kses post filtering—a function used to sanitize post content—because it contains no HTML tags and remains intact within the block comment's JSON attributes, reaching the walker unescaped during rendering.
Recommendations Update RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg to version 1.5.3 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15650

Affected Products

Rt Mega Menu