Junglewise Threat Intelligence

CVE-2026-14855: RT Mega Menu stored cross-site scripting in CSS parameter

CVE-2026-14855 · Severity: medium · CVSS 6.4 · Published 2026-09-18

Executive brief

The RT Mega Menu WordPress plugin fails to properly validate user input in the CSS configuration parameters, allowing authenticated users to inject malicious scripts. When other users visit pages containing the injected code, their browsers execute the attacker's scripts, potentially enabling account compromise, credential theft, or malicious redirects.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw caused by insufficient input sanitization and output escaping of the 'css[left]' parameter in the RT Mega Menu plugin's AJAX request handler. Authenticated attackers with Subscriber-level privileges or higher can inject arbitrary JavaScript code that persists in the database and executes in the browsers of all users who view the affected page. The vulnerability requires the attacker to already have authenticated access to the WordPress installation. The injected code executes in the context of the website and can perform actions on behalf of the victim.

Affected products

  • RT Mega Menu up to 1.5.1

Timeline

  • 2026-09-18: disclosed

References

Related threats