Junglewise Threat Intelligence

CVE-2026-92465: Themeum WP Mega Menu SQL injection

CVE-2026-92465 · Severity: high · CVSS 7.6 · Published 2026-09-16

Executive brief

WP Mega Menu is a WordPress plugin that creates custom navigation menus. A SQL injection vulnerability allows attackers to read, modify, or delete the website's entire database, including user accounts and private data, potentially exposing sensitive business information and customer details.

Technical details

A SQL injection vulnerability exists in WP Mega Menu versions up to 1.4.2 due to improper neutralization of special elements in SQL commands. The vulnerability allows blind SQL injection attacks that enable attackers to query and manipulate the database. While the exact vulnerable component and attack vector details are not fully documented, the issue requires administrator-level privileges to exploit. No official patch is currently available; affected users should update to a patched version when available or implement database access controls.

Affected products

  • Themeum WP Mega Menu through 1.4.2

Timeline

  • 2026-09-16: disclosed: Published by Patchstack
  • 2026-09-08: other: Reported to Patchstack

References