Impact
The Admin Menu Organizer plugin for WordPress has a flaw where user input is not properly sanitized before being reflected in the browser. The unchecked data can be injected with arbitrary HTML or JavaScript, and when a victim visits a crafted URL or clicks a malicious link the script executes within the context of the WordPress site, allowing exfiltration of authentication cookies, session hijacking, or the display of fake content.
Affected Systems
The vulnerability affects the phpdevca Admin Menu Organizer plugin for WordPress, including all releases from the initial distribution through version 1.0.1. Users who have not upgraded beyond 1.0.1 remain exposed.
Risk and Exploitability
The CVSS score of 7.1 denotes a high‑impact vulnerability. The EPSS score of less than 1 % suggests that, although the flaw is serious, it is unlikely to be widely exploited at present, likely requiring a socially engineered link or in‑site click‑through. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw remotely by supplying a crafted URL; the primary impact is client‑side code execution in the victim’s browser, which can compromise session integrity and facilitate defacement.
OpenCVE Enrichment
EUVD