Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jetmonsters Mega Menu Block getwid-megamenu allows Stored XSS.This issue affects Mega Menu Block: from n/a through <= 1.0.6.
Published: 2025-05-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation that allows an attacker to store malicious scripts in the Mega Menu Block plugin, leading to stored cross‑site scripting. An attacker who can inject content could cause arbitrary JavaScript execution in the browsers of any visitor to a site that uses the affected menu, potentially enabling session hijacking, credential theft, or defacement. This flaw results in a CVSS score of 6.5, indicating a moderate severity risk. The weakness is identified as CWE‑79, reflecting insufficient input validation and sanitization.

Affected Systems

Jetmonsters Mega Menu Block (getwid‑megamenu) for WordPress is affected for all released versions up to and including 1.0.6. The issue is present in the plugin’s storage of menu configuration data and does not affect later releases beyond 1.0.6.

Risk and Exploitability

The EPSS score is reported as less than 1 %, suggesting that while exploitation is possible, it is currently considered unlikely in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is through the plugin’s administrative interface, where a user with sufficient privileges can create or edit menu items and embed malicious code. An attacker could then trigger the stored script by having any user view the affected menu. The moderate CVSS score, combined with the low EPSS, indicates that the overall risk is moderate but should still be addressed promptly, especially in environments that expose the plugin’s configuration to users with editing rights.

Generated by OpenCVE AI on April 30, 2026 at 12:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Jetmonsters Mega Menu Block to version 1.0.7 or later to remove the stored XSS flaw
  • Ensure that any existing menu items containing user‑supplied content are cleaned or removed; apply a content filter that escapes or strips script tags
  • If an update is not immediately possible, restrict access to the plugin’s configuration area to trusted administrators or disable the plugin entirely until a fix is applied

Generated by OpenCVE AI on April 30, 2026 at 12:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28177 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jetmonsters Mega Menu Block allows Stored XSS. This issue affects Mega Menu Block: from n/a through 1.0.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jetmonsters Mega Menu Block allows Stored XSS. This issue affects Mega Menu Block: from n/a through 1.0.6. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jetmonsters Mega Menu Block getwid-megamenu allows Stored XSS.This issue affects Mega Menu Block: from n/a through <= 1.0.6.
Title WordPress Mega Menu Block <= 1.0.6 - Cross Site Scripting (XSS) Vulnerability WordPress Mega Menu Block plugin <= 1.0.6 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 May 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jetmonsters Mega Menu Block allows Stored XSS. This issue affects Mega Menu Block: from n/a through 1.0.6.
Title WordPress Mega Menu Block <= 1.0.6 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:54.347Z

Reserved: 2025-05-19T14:13:09.842Z

Link: CVE-2025-48258

cve-icon Vulnrichment

Updated: 2025-05-19T15:08:48.788Z

cve-icon NVD

Status : Deferred

Published: 2025-05-19T15:15:28.887

Modified: 2026-04-23T15:30:58.923

Link: CVE-2025-48258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T12:45:22Z

Weaknesses