Junglewise Threat Intelligence

CVE-2026-59559: Themewant RT Mega Menu Subscriber XSS in Mega Menu Builder

CVE-2026-59559 · Severity: medium · CVSS 6.5 · Published 2026-07-27

Executive brief

A vulnerability in the RT Mega Menu plugin for WordPress allows users with low-level 'Subscriber' accounts to inject malicious scripts into the website. If an administrator or another visitor views the affected area, these scripts could steal session information, redirect users to malicious sites, or deface the website. This affects site owners using the Elementor or Gutenberg editors to build custom navigation menus.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the RT Mega Menu plugin (versions 1.5.1 and below) for WordPress. The flaw stems from improper neutralization of user-supplied input (CWE-79) within the menu builder components. An authenticated attacker with Subscriber-level privileges can inject malicious JavaScript payloads that are stored on the server. When a privileged user (such as an administrator) interacts with the affected page or component, the script executes in their browser context, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 1.5.2.

Affected products

  • themewant RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1

Timeline

  • 2026-05-20: other: Vulnerability reported by researcher anhcd05
  • 2026-07-27: advisory: Advisory published by Patchstack and NVD
  • 2026-07-27: patched: Patch released in version 1.5.2

References

Related threats