SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-11872

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The Clever Mega Menu for Visual Composer plugin for WordPress is vulnerable due to a lack of nonce or capability checks in an AJAX action, enabling any authenticated user, including those with low-level Subscriber roles, to modify navigation menu item metadata. This could lead to unauthorized changes in the site's public navigation, potentially impacting the integrity of the site's presentation and user experience. WordPress site administrators, especially those using this plugin, should prioritize addressing this vulnerability to prevent unauthorized content manipulation.

CVE
CVE-2026-11872
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%
WordPress

Original NVD Description

The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public navigation.