Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in littlejon LJ Custom Menu Links lj-custom-menu-links allows Reflected XSS.This issue affects LJ Custom Menu Links: from n/a through <= 2.5.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The LJ Custom Menu Links plugin for WordPress contains an improper input neutralization flaw that permits reflected cross‑site scripting (CWE‑79). When an attacker crafts a malicious URL and lures a user to visit it, the arbitrary script is injected into the page that the victim’s browser renders, potentially enabling cookie theft, session hijacking, defacement, or redirection to malicious sites. The vulnerability does not appear to allow further compromise beyond the browser context, but it can lead to significant breach of confidentiality and integrity for affected users.

Affected Systems

WordPress sites that use the littlejon LJ Custom Menu Links plugin with version 2.5 or earlier are affected. No specific sub‑versions are enumerated beyond the overall <= 2.5 range.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high severity. The EPSS of less than 1% suggests that exploitation activity is rare at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers would most likely target users by delivering a crafted URL that the affected plugin renders without proper sanitization, inferring that the primary attack vector is a direct link entry or menu parameter injection. Because the flaw is reflected, an active network connection is not required; a victim must open a URL or click a menu link that contains the malicious payload.

Generated by OpenCVE AI on May 1, 2026 at 14:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the LJ Custom Menu Links plugin to a version newer than 2.5 or remove the plugin entirely.
  • If an upgrade is delayed, implement strict output encoding or input sanitization on all menu link fields to neutralize injected scripts, or switch to a vetted menu‑link solution that properly escapes user data.
  • Audit the site for other reflected XSS opportunities and monitor user traffic for unusual script injection activity.

Generated by OpenCVE AI on May 1, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5670 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound LJ Custom Menu Links allows Reflected XSS. This issue affects LJ Custom Menu Links: from n/a through 2.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound LJ Custom Menu Links allows Reflected XSS. This issue affects LJ Custom Menu Links: from n/a through 2.5. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in littlejon LJ Custom Menu Links lj-custom-menu-links allows Reflected XSS.This issue affects LJ Custom Menu Links: from n/a through <= 2.5.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 12 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound LJ Custom Menu Links allows Reflected XSS. This issue affects LJ Custom Menu Links: from n/a through 2.5.
Title WordPress LJ Custom Menu Links Plugin <= 2.5 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:23.471Z

Reserved: 2025-01-16T11:31:27.428Z

Link: CVE-2025-23881

cve-icon Vulnrichment

Updated: 2025-05-12T15:28:18.989Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:48.290

Modified: 2026-06-17T08:57:40.077

Link: CVE-2025-23881

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')