ZeroHour

CVE-2026-92465

moderate

Blind SQL Injection in Themeum WP Mega Menu WordPress Plugin

CVSS 3.1
7.6 high
EPSS
Published
()
Modified
AI analysis

The WP Mega Menu plugin by Themeum fails to properly neutralize special elements in an SQL command, allowing blind SQL injection (CWE-89) in all versions through 1.4.2. Per the CVSS vector, exploitation requires a network-accessible attacker who already holds high privileges on the WordPress site (e.g., an administrator account), with no user interaction and low attack complexity. Through blind injection, an attacker can extract arbitrary data from the site database character by character, potentially exposing user credentials, password hashes, and other sensitive information, with minor availability impact. Any WordPress site running WP Mega Menu at version 1.4.2 or earlier is affected. No public proof-of-concept, listings in CISA's KEV catalog, or reports of in-the-wild exploitation are currently known.

What to do: Update WP Mega Menu to the latest release (any version newer than 1.4.2 once available from Themeum/WordPress.org), or deactivate the plugin until a patched version is published. Restrict and audit administrator-level accounts, since the flaw requires high-privilege access to trigger, and monitor Patchstack's advisory for the fixed version details. Check plugin versions across your WordPress estate (e.g., via WP-CLI or a vulnerability scanner) to confirm no site is running 1.4.2 or earlier.

Affected
Themeum WP Mega Menu (WordPress plugin)all versions through 1.4.2 (n/a to 1.4.2)
Estimated exposure
moderate≈10,000–20,000 sites (plugin listed at roughly 10k+ active installs on WordPress.org) — Themeum's WP Mega Menu free plugin has historically shown on the order of 10,000+ active installations on WordPress.org, so the plausible affected population is a five-figure number of sites; practical exploitation is further limited by…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.

Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.