CVE Explorer
CVE-2026-11872
The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public navigation.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"Clever Mega Menu for Visual Composer","vendor":"Unknown","versions":[{"lessThanOrEqual":"1.0.1","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:26097754645958a06135ed34e35dc25f92b2c411b76c2d70e966ccc26b549e72 · sha256:b7c68dabdc6eb59a… · /containers/cna/affected/0
CWE assertions
1 source assertion{"description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:26097754645958a06135ed34e35dc25f92b2c411b76c2d70e966ccc26b549e72 · sha256:b7c68dabdc6eb59a… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/23c9232c-73e1-477e-a0b5-bceebb6ab6dd/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:26097754645958a06135ed34e35dc25f92b2c411b76c2d70e966ccc26b549e72 · sha256:b7c68dabdc6eb59a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.