Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md Abunaser Khan Advance Food Menu advance-food-menu allows Stored XSS.This issue affects Advance Food Menu: from n/a through <= 1.0.
Published: 2025-08-28
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a stored Cross‑Site Scripting (XSS) flaw that occurs because user input is not properly neutralized before being included in generated web pages. An attacker can inject malicious JavaScript that will run whenever the affected page is viewed, potentially allowing defacement, cookie theft, or redirection of site visitors. The flaw enables an attacker to alter the presentation and behavior of the website for all users who access the vulnerable page.

Affected Systems

The flaw affects the Advance Food Menu plugin developed by Md Abunaser Khan. Any installation using version 1.0 or earlier is vulnerable. The exact release numbers are unspecified beyond the upper bound of 1.0, so all releases up to that point require review.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score is below 1 %, suggesting that the likelihood of exploitation in the wild is low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would likely occur by supplying a crafted payload to a plugin input that is stored and later displayed to site visitors, so an attacker would need access to a functioning input endpoint—typically an administrator or user with permission to create or edit menu items. Because the user interface is web‑based, authenticated or even public access could be sufficient depending on how the plugin processes data.

Generated by OpenCVE AI on April 30, 2026 at 15:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest version of Advance Food Menu (if a new version that fixes the stored XSS exists).
  • If no patched release is available, permanently delete or deactivate the plugin to eliminate the stored XSS vector.
  • Run a security scan of all webpage content and the plugin’s data directories to remove any injected scripts.
  • Apply server‑side input validation or sanitization to vulnerable fields if the vulnerability is reproduced by remaining input fields.

Generated by OpenCVE AI on April 30, 2026 at 15:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26036 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md Abunaser Khan Advance Food Menu allows Stored XSS. This issue affects Advance Food Menu: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md Abunaser Khan Advance Food Menu allows Stored XSS. This issue affects Advance Food Menu: from n/a through 1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md Abunaser Khan Advance Food Menu advance-food-menu allows Stored XSS.This issue affects Advance Food Menu: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Thu, 28 Aug 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 28 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md Abunaser Khan Advance Food Menu allows Stored XSS. This issue affects Advance Food Menu: from n/a through 1.0.
Title WordPress Advance Food Menu plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:56.361Z

Reserved: 2025-05-19T14:14:03.305Z

Link: CVE-2025-48323

cve-icon Vulnrichment

Updated: 2025-08-28T13:33:09.632Z

cve-icon NVD

Status : Deferred

Published: 2025-08-28T13:15:51.543

Modified: 2026-04-23T15:31:06.307

Link: CVE-2025-48323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T15:45:40Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')