PatchSiren

RT Mega Menu CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review RT Mega Menu CVE published 2026-08-02

CVE-2026-15385

The RT Mega Menu WordPress plugin before 1.5.2 has a vulnerability allowing a subscriber-level user to enable the mega menu on a site and store a malicious style value. This value is rendered without output escaping into a style attribute on the public navigation, enabling the persistence of a JavaScript event handler. The event handler executes for every visitor who hovers over the navigation, including [truncated]