Review
RT Mega Menu
CVE published 2026-08-02
CVE-2026-15385
The RT Mega Menu WordPress plugin before 1.5.2 has a vulnerability allowing a subscriber-level user to enable the mega menu on a site and store a malicious style value. This value is rendered without output escaping into a style attribute on the public navigation, enabling the persistence of a JavaScript event handler. The event handler executes for every visitor who hovers over the navigation, including [truncated]