What is CVE-2026-59559?
CVE-2026-59559 is a stored Cross Site Scripting (XSS) vulnerability found in the RT Mega Menu plugin affecting versions <= 1.5.1. An authenticated attacker with Subscriber-level permissions could inject malicious scripts that execute when a user accesses an affected page. Users should update the plugin to the latest version to mitigate this risk.
Azərbaycanca: CVE-2026-59559 'RT Mega Menu' plaginində aşkar edilmiş saxlanılan Subscriber Cross Site Scripting (XSS) zəifliyidir. Bu boşluq Elementor & Gutenberg üçün nəzərdə tutulmuş plaginin 1.5.1 və daha əvvəlki versiyalarına təsir edir. Bu zəiflik vasitəsilə 'Subscriber' səviyyəsində icazəsi olan autentifikasiya olunmuş hücumçu veb səhifələrə zərərli skriptlər yerləşdirə bilər. İstifadəçilərə plaginin son versiyasına yeniləmə etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the RT Mega Menu plugin are affected by CVE-2026-59559?
CVE-2026-59559 affects the RT Mega Menu plugin versions 1.5.1 and earlier.
What level of permission does an attacker need to exploit CVE-2026-59559?
An attacker must be authenticated with Subscriber-level permissions to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.