themewant has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 6.4 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.4
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Weakness classes
Products
- RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg 2
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-15650Medium· 6.4The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute in all versions up to, and including, 1.5.2 due to insufficient inpu…35CVE-2026-14855Medium· 6.4The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping35
themewant vulnerabilities
CVEs affecting themewant, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-15650Medium· 6.4The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute in all versions up to, and including, 1.5.2 due to insufficient inpu…
The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute in all versions up to, and including, 1.5.2 due to insufficient inpu…
▾ Sunlitthemewant · RT Mega Menu – Mega Menu Builder for Elementor & GutenbergEPSS 0.21%via NVD
CVE-2026-14855Medium· 6.4The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping
The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possib…
▾ Sunlitthemewant · RT Mega Menu – Mega Menu Builder for Elementor & GutenbergEPSS 0.20%via NVD