Cross-Site Scripting in RT Mega Menu for Elementor & Gutenberg by WordPress
CVE-2026-59559

6.5MEDIUM

What is CVE-2026-59559?

A Cross-Site Scripting (XSS) vulnerability has been identified in the RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin. This flaw allows unauthenticated users to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, content manipulation, or redirection to malicious sites. Users of version 1.5.1 and earlier are particularly affected and should apply updates to safeguard against possible threats.

Affected Version(s)

RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

anhcd05 | Patchstack Bug Bounty Program
.