Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Unknown RT Mega Menu — RT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L R C L L N 5.4 .0013 3.3 —
AFFECTED
Product Versions Fixed
RT Mega Menu unspecified —
TIMELINE
Jul 10 Reserved by WPScan
Aug 2 Published (CNA: WPScan)
Aug 3 EXPLOIT PUBLISHED — CVE-2026-15385 (Unknown RT Mega Menu). Public exploit reference added.
Description
The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; its only gate is a nonce that any logged-in user can read from a standard admin page. A subscriber-level user can therefore enable the mega menu on a site menu and store a menu-item style value that is rendered, without output escaping, into a style attribute on the public navigation. By breaking out of that attribute the user persists a JavaScript event handler that executes for every visitor who hovers the navigation, including administrators, leading to session/site takeover.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 10, 2026 | Reserved | Reserved by WPScan |
| August 2, 2026 | Published | Published (CNA: WPScan) |
| August 3, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-15385 (Unknown RT Mega Menu). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Unknown | RT Mega Menu | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-15385 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.