CVE-2026-92465
moderateBlind SQL Injection in Themeum WP Mega Menu WordPress Plugin
The WP Mega Menu plugin by Themeum fails to properly neutralize special elements in an SQL command, allowing blind SQL injection (CWE-89) in all versions through 1.4.2. Per the CVSS vector, exploitation requires a network-accessible attacker who already holds high privileges on the WordPress site (e.g., an administrator account), with no user interaction and low attack complexity. Through blind injection, an attacker can extract arbitrary data from the site database character by character, potentially exposing user credentials, password hashes, and other sensitive information, with minor availability impact. Any WordPress site running WP Mega Menu at version 1.4.2 or earlier is affected. No public proof-of-concept, listings in CISA's KEV catalog, or reports of in-the-wild exploitation are currently known.
What to do: Update WP Mega Menu to the latest release (any version newer than 1.4.2 once available from Themeum/WordPress.org), or deactivate the plugin until a patched version is published. Restrict and audit administrator-level accounts, since the flaw requires high-privilege access to trigger, and monitor Patchstack's advisory for the fixed version details. Check plugin versions across your WordPress estate (e.g., via WP-CLI or a vulnerability scanner) to confirm no site is running 1.4.2 or earlier.
| Themeum WP Mega Menu (WordPress plugin) | all versions through 1.4.2 (n/a to 1.4.2) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.