PT-2026-103041 · WordPress · Wp Mobile Menu
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WP Mobile Menu versions prior to 2.9
Description
Insufficient nonce verification during the settings import process allows an attacker to perform a cross-site request within an administrator's session to import arbitrary settings. Because these imported values are output unescaped to all visitors, this leads to Stored Cross-Site Scripting (XSS), a condition where malicious scripts are permanently stored on the server and executed in the browsers of users visiting the site.
Recommendations
Update WP Mobile Menu to version 2.9 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Mobile Menu