CVE-2026-92465: WordPress WP Mega Menu plugin <= 1.4.2 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection.
This issue affects WP Mega Menu: from n/a through 1.4.2.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs high privileges and can exploit the issue remotely without user interaction. This reduces exposure to unauthenticated visitors but leaves sites at risk if a highly privileged account is compromised or misused.
Which versions are affected?
WP Mega Menu versions through 1.4.2 are affected. The available data does not identify a fixed version.
What is the likely impact of successful exploitation?
The issue allows blind SQL injection. The supplied severity vector indicates high confidentiality impact, no integrity impact, and low availability impact, with effects potentially extending beyond the vulnerable component's security scope.