CVE-2026-11872: Unknown Clever Mega Menu For Visual Composer
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public navigation.
Affected products
- Unknown Clever Mega Menu For Visual Composer: up to and including 1.0.1
Published 2026-08-02. Last modified 2026-08-26.