WordPress security by component
Clever Mega Menu for Visual Composer
Plugin description
Clever Mega Menu for Visual Composer is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 02, 2026; the highest published CVSS base score is 4.3.
Plugin slug:
clever-mega-menu-for-visual-composerLatest vulnerability
CVE-2026-11872: Clever Mega Menu lets Subscribers overwrite public navigation metadata
Clever Mega Menu for Visual Composer through 1.0.1 exposes a navigation-menu metadata update AJAX action without nonce or capability checks. Any authenticated user, including a Subscriber, can overwrite content and settings for menu items rendered in the site's public navigation. The CNA record does not establish script execution and does not disclose the action, menu-item identifier, metadata fields or update function.
| Safe version |
|
||
|---|---|---|---|
| Aug 02, 2026 |
CVE-2026-11872
Clever Mega Menu lets Subscribers overwrite public navigation metadata
Clever Mega Menu for Visual Composer through 1.0.1 exposes a navigation-menu metadata update AJAX action without nonce or capability checks. Any authenticated user, including a Subscriber, can overwrite content and settings for menu items rendered in the site's public navigation. The CNA record does not establish script execution and does not disclose the action, menu-item identifier, metadata fields or update function.
|
> 1.0.1 |
CVE4.3
NVDPending
|