CVE-2026-11872

The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public navigation.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-02 06:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-11872

Mitre link : CVE-2026-11872

CVE.ORG link : CVE-2026-11872


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control