---
id: CVE-2026-15385
title: >-
  The RT Mega Menu  WordPress plugin before 1.5.2 does not perform a capability
  check on the AJAX action that saves mega-menu configuration and per-menu-item
  settings; its only gate is a nonce that any logged-in user can read from a
  standa…
summary: >-
  The RT Mega Menu  WordPress plugin before 1.5.2 does not perform a capability
  check on the AJAX action that saves mega-menu configuration and per-menu-item
  settings; its only gate is a nonce that any logged-in user can read from a
  standa…
severity: none
published: '2026-08-02'
updated: '2026-08-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15385'
references:
  - url: 'https://wpscan.com/vulnerability/b13b19c6-b6e1-45eb-95f3-ac334bda8b84/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-08-02T13:18:29.147Z'
epss: 0.00226
epssPercentile: 0.11823
---

## Overview

The RT Mega Menu  WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; its only gate is a nonce that any logged-in user can read from a standard admin page. A subscriber-level user can therefore enable the mega menu on a site menu and store a menu-item style value that is rendered, without output escaping, into a style attribute on the public navigation. By breaking out of that attribute the user persists a JavaScript event handler that executes for every visitor who hovers the navigation, including administrators, leading to session/site takeover.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
