Cross-Site Scripting in RT Mega Menu for Elementor & Gutenberg by WordPress
CVE-2026-59559
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 July 2026
What is CVE-2026-59559?
A Cross-Site Scripting (XSS) vulnerability has been identified in the RT Mega Menu β Mega Menu Builder for Elementor & Gutenberg plugin. This flaw allows unauthenticated users to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, content manipulation, or redirection to malicious sites. Users of version 1.5.1 and earlier are particularly affected and should apply updates to safeguard against possible threats.
Affected Version(s)
RT Mega Menu β Mega Menu Builder for Elementor & Gutenberg <= 1.5.1