CVE-2026-11872
Received Received - Intake

Clever Mega Menu for Visual Composer Authenticated Menu Overwrite

Vulnerability report for CVE-2026-11872, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-02

Last updated on: 2026-08-02

Assigner: WPScan

Description

The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public navigation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-02
Last Modified
2026-08-02
Generated
2026-08-02
AI Q&A
2026-08-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
clever_mega_menu visual_composer to 1.0.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Clever Mega Menu for Visual Composer WordPress plugin up to version 1.0.1. It lacks a nonce or capability check in an AJAX action that updates navigation menu item metadata. This allows any authenticated user, including those with Subscriber roles, to modify menu item content and settings that appear in the site's public navigation.

Detection Guidance

Check for unauthorized changes in WordPress navigation menu items by inspecting the database or using WordPress admin tools. Look for AJAX calls to the vulnerable plugin endpoint.

Impact Analysis

An attacker could change the content or settings of menu items visible to all users. This might include altering links, text, or other navigation elements, potentially leading to misinformation, phishing, or disruption of site functionality.

Compliance Impact

This vulnerability allows any authenticated user, including low-privilege Subscribers, to modify navigation menu content and settings. This could potentially lead to unauthorized changes in how user data or privacy notices are displayed, which may impact compliance with GDPR or HIPAA if such changes affect data handling visibility or user consent mechanisms.

Mitigation Strategies

Update the Clever Mega Menu plugin to the latest version if available. If not, consider disabling the plugin until a patch is released. Restrict user roles to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11872. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart