Executive brief
Clever Mega Menu for Visual Composer is a WordPress plugin that customizes site navigation menus. The plugin fails to verify user permissions or security tokens in an AJAX action, allowing low-privilege users (even Subscribers) to modify public menu content that all visitors see. An attacker can inject malicious code into navigation menus, affecting every visitor to the site.
Technical details
The vulnerability is a broken access control (CWE-284) in the save_clever_menu_item AJAX action. The plugin does not implement nonce verification or capability checks before updating menu item metadata (_clever_mega_menu_item_meta_content and _clever_mega_menu_item_meta_settings). Any authenticated user, including Subscribers with minimal permissions, can POST to wp-admin/admin-ajax.php and overwrite menu item metadata. The injected content is rendered in the public frontend via do_shortcode() and wp_kses_post(), allowing stored shortcode injection. No official patch is available as of the advisory publication date.
Affected products
- Clever Mega Menu Clever Mega Menu for Visual Composer through 1.0.1
Timeline
- 2026-07-21: disclosed
- 2026-08-02: advisory: NVD publication date