What the vulnerability does
01Description
The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the hmenu_delete_menu() function in all versions up to, and including, 1.16.5. This makes it possible for unauthenticated attackers to delete arbitrary directories on the server.
Explanation of Vulnerability in Simple Terms
02Summary
The Hero Mega Menu plugin for WordPress does not properly check user permissions before allowing certain actions. A logged-in user with low privileges can perform administrative functions they should not have access to, potentially disrupting site functionality. All versions up to 1.16.5 are affected. Update to a version newer than 1.16.5 to resolve this issue.
What an attacker can do
03Attacker Capabilities
A low-privilege logged-in user can perform administrative actions they should not have access to.
Potential impact on your site
04Site Impact
Unauthorized users can disrupt menu configuration and site functionality without admin approval.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
06Disclosure timeline
March 5, 2025
CVE published
April 8, 2026
Record updated