← back
CVE-2026-91832highCWE-79

WP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRF

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 7.1epss 0.1%
exploitation probability
0.1%top 100% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Affected products
Unknown · WP Mobile Menu
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.