CVE-2026-65433 is a Subscriber Broken Access Control vulnerability in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin versions <= 1.5.1. The vulnerability has a CVSS score of 6.5 and a CVSS severity of MEDIUM. Users of the affected plugin should assess and potentially update to a patched version. The CVE record was published on 2026-07-27T15:17:08.480Z and has not been modified since the [truncated]
A Cross Site Scripting (XSS) vulnerability exists in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin versions <= 1.5.1. This issue allows subscribers to inject malicious scripts, potentially leading to security breaches. Users of the affected plugin should update to a patched version to prevent XSS attacks. The CVSS score for this vulnerability is 6.5, indicating a medium severity level.
CVE-2026-56028 is a critical unauthenticated privilege escalation vulnerability in Easy Elements for Elementor – Addons & Website Templates versions up to and including 1.4.9. The vulnerability has a CVSS score of 9.8 and is considered critical. The CVE was published on June 26, 2026, and last modified on June 29, 2026. The vulnerability allows an attacker to escalate privileges without authentication, po [truncated]
CVE-2026-9018 affects the Easy Elements for Elementor – Addons & Website Templates WordPress plugin through version 1.4.5. The supplied vulnerability description says the plugin’s public registration flow can write attacker-controlled custom meta into a newly created user account, which can overwrite sensitive fields such as wp_capabilities and turn the account into an administrator. The exposure depends [truncated]
The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress contains a critical privilege escalation vulnerability in versions up to and including 1.4.4. The `easyel_handle_register` function fails to restrict user roles during registration, allowing unauthenticated attackers to specify arbitrary roles including 'administrator' during account creation. This grants immediate administr [truncated]