What is CVE-2026-15385?
CVE-2026-15385 is a missing capability check vulnerability in the 'RT Mega Menu' WordPress plugin before version 1.5.2. The AJAX action saving mega-menu configurations uses only a nonce that any logged-in user can read, allowing subscriber-level users to modify settings. It is recommended to update the plugin to version 1.5.2 or later immediately.
Azərbaycanca: CVE-2026-15385 'RT Mega Menu' WordPress plugin-nin 1.5.2-dən əvvəlki versiyalarında aşkar edilmiş imtiyaz yoxlaması zəifliyidir. AJAX əməliyyatı üzərində 'nonce' qoruma mexanizmi istənilən daxil olmuş istifadəçi tərəfindən oxuna bildiyindən, aşağı səviyyəli 'subscriber' istifadəçilər menyu konfiqurasiyasını dəyişdirə bilər. Plugin-i dərhal 1.5.2 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
Which plugin and which versions are affected by CVE-2026-15385?
CVE-2026-15385 affects the 'RT Mega Menu' WordPress plugin in versions before 1.5.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.