Impact
The Nav Menu Manager plugin for WordPress contains a stored cross‑site scripting flaw. Improper input neutralization allows attackers to inject malicious scripts into menu items that are rendered on the website’s pages. If executed in the browser of any site visitor, such scripts can steal session cookies, deface content, or redirect users to malicious sites. This vulnerability is classified as CWE‑79, a classic input validation issue.
Affected Systems
The flaw affects all installations of the Nav Menu Manager plugin produced by Robert Noakes that are version 3.2.5 or earlier. WordPress sites that have this plugin loaded are potentially compromised until the plugin is upgraded or removed.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity flaw, while the EPSS score of less than 1% suggests a very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need authenticated access to the WordPress administrative interface that can edit menu items, and then submit malicious payloads that are stored by the plugin. With sufficient privileges, the stored scripts could run for all users who view the affected pages.
OpenCVE Enrichment
EUVD