Junglewise Threat Intelligence

CVE-2026-65433: Themewant RT Mega Menu broken access control

CVE-2026-65433 · Severity: medium · CVSS 6.5 · Published 2026-07-27

Executive brief

A security vulnerability exists in the RT Mega Menu plugin for WordPress, which is used to create advanced navigation menus. This flaw allows users with basic 'Subscriber' accounts to perform actions they should not be authorized to do. An attacker could potentially modify website menu configurations, leading to unauthorized site changes or disruption of the user experience.

Technical details

The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress (versions 1.5.1 and below) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This allows an authenticated attacker with Subscriber-level permissions to execute functions that should be restricted to higher-privileged users. The vulnerability is exploitable via network requests without user interaction. The issue is resolved in version 1.5.2, which introduces proper authorization validation.

Affected products

  • themewant RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1

Timeline

  • 2026-06-10: other: Reported by researcher luc
  • 2026-07-27: disclosed: Vulnerability published by Patchstack
  • 2026-07-27: patched: Version 1.5.2 released to address the issue

References

Related threats