Executive brief
RT Mega Menu is a WordPress plugin that enables advanced navigation menu features. Due to missing permission checks in its configuration save function, a subscriber-level user (the lowest-privilege WordPress account) can inject malicious code into menu styling. This code persists on the site's public navigation and executes for every visitor—including administrators—when they interact with the menu, enabling account takeover and site compromise.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the plugin's AJAX handler for saving mega-menu configuration. The plugin validates requests using only a nonce that is publicly readable from the admin profile page, without checking the user's WordPress capabilities (permissions). An attacker with subscriber-level access can craft a POST request to the rtmega_update_menu_options AJAX action, injecting arbitrary JavaScript into the CSS field of menu items. The malicious CSS is stored in the database and rendered without output escaping into style attributes on the public-facing navigation menu. This allows the injected JavaScript to execute for all site visitors, including administrators, leading to session hijacking and site takeover. The vulnerability affects RT Mega Menu versions before 1.5.2 and is fixed in 1.5.2.
Affected products
- RT Mega Menu before 1.5.2
Timeline
- 2026-07-20: disclosed
- 2026-08-02: advisory
- 2026-: patched: Fixed in version 1.5.2