← WordPress Vulnerabilities
WordPress security by component

Clever Mega Menu for Visual Composer

Clever Mega Menu for Visual Composer is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 02, 2026; the highest published CVSS base score is 4.3.

Plugin slug: clever-mega-menu-for-visual-composer

CVE-2026-11872: Clever Mega Menu lets Subscribers overwrite public navigation metadata

Clever Mega Menu for Visual Composer through 1.0.1 exposes a navigation-menu metadata update AJAX action without nonce or capability checks. Any authenticated user, including a Subscriber, can overwrite content and settings for menu items rendered in the site's public navigation. The CNA record does not establish script execution and does not disclose the action, menu-item identifier, metadata fields or update function.

PublishedAug 02, 2026
Known safe version> 1.0.1
Published vulnerabilities for clever-mega-menu-for-visual-composer
Safe version
Aug 02, 2026 CVE-2026-11872
Clever Mega Menu lets Subscribers overwrite public navigation metadata
Clever Mega Menu for Visual Composer through 1.0.1 exposes a navigation-menu metadata update AJAX action without nonce or capability checks. Any authenticated user, including a Subscriber, can overwrite content and settings for menu items rendered in the site's public navigation. The CNA record does not establish script execution and does not disclose the action, menu-item identifier, metadata fields or update function.
> 1.0.1
CVE4.3
NVDPending