WordPress · Wp Mobile Menu · CVE-2026-91832
**Name of the Vulnerable Software and Affected Versions**
WP Mobile Menu versions prior to 2.9
**Description**
Insufficient nonce verification during the settings import process allows an attacker to perform a cross-site request within an administrator's session to import arbitrary settings. Because these imported values are output unescaped to all visitors, this leads to Stored Cross-Site Scripting (XSS), a condition where malicious scripts are permanently stored on the server and executed in the browsers of users visiting the site.
**Recommendations**
Update WP Mobile Menu to version 2.9 or later.