Impact
The Custom Admin Menu plugin for WordPress releases up to 1.0.0 fails to sanitize and escape a request parameter before echoing it back into the page. This omission creates a reflected XSS vulnerability that can be triggered by an attacker constructing a malicious URL. High‑privilege users, such as site administrators, visiting such a URL could have arbitrary scripts executed in their browser session, potentially leading to session hijacking, theft of credentials, or injection of malicious content.
Affected Systems
WordPress sites using the Custom Admin Menu plugin with a version less than or equal to 1.0.0 are affected. No specific version list beyond the cap of 1.0.0 is provided.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity impact. The EPSS score of <1% suggests that, as of the latest data, the probability of exploitation is low, and the vulnerability is not currently recorded in the CISA KEV catalog. The likely attack vector is a crafted URL accessed by an authenticated administrator; the attacker need not have site access but must lure the admin to the vulnerable link.
OpenCVE Enrichment