Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chaimchaikin Admin Menu Groups admin-menu-groups allows Stored XSS.This issue affects Admin Menu Groups: from n/a through <= 0.1.2.
Published: 2025-08-27
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability occurs because the plugin fails to sanitize user input used in admin menu rendering, enabling a stored cross‑site scripting attack. An attacker with sufficient access to create or edit menu items can inject arbitrary scripts that will run in the browsers of site administrators. The flaw is classified as CWE‑79, allowing potential compromise of confidentiality, integrity and availability of the administration interface, and could lead to credential theft or session hijacking. The CVSS score of 5.9 indicates a moderate severity for this exploit.

Affected Systems

The issue affects the WordPress plugin Admin Menu Groups by chaimchaikin, versions from the earliest release through 0.1.2. Any WordPress site that has this plugin installed and is running a vulnerable version is exposed.

Risk and Exploitability

The EPSS score of less than 1% suggests that exploitation is unlikely but still possible. The vulnerability is not listed in CISA KEV, meaning no known public exploits have been reported yet. The likely attack vector is an attacker who has or can obtain administrator privileges to create or modify menu items; once injected, the payload will execute whenever an admin visits the page that displays the menu, enabling arbitrary JavaScript execution in the admin context. Given the moderate CVSS score and low EPSS, the risk remains moderate, warranting proactive mitigation.

Generated by OpenCVE AI on April 30, 2026 at 08:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Admin Menu Groups plugin to a version later than 0.1.2, applying the vendor’s official fix.
  • If an update cannot be performed immediately, remove or disable the plugin entirely to eliminate the stored XSS vector.
  • As a temporary workaround, restrict menu‑editing capabilities to only trusted administrators and ensure no other site users have permission to alter menu items.

Generated by OpenCVE AI on April 30, 2026 at 08:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28279 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chaimchaikin Admin Menu Groups allows Stored XSS.This issue affects Admin Menu Groups: from n/a through 0.1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chaimchaikin Admin Menu Groups allows Stored XSS.This issue affects Admin Menu Groups: from n/a through 0.1.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chaimchaikin Admin Menu Groups admin-menu-groups allows Stored XSS.This issue affects Admin Menu Groups: from n/a through <= 0.1.2.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 27 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 Aug 2025 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 27 Aug 2025 03:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chaimchaikin Admin Menu Groups allows Stored XSS.This issue affects Admin Menu Groups: from n/a through 0.1.2.
Title WordPress Admin Menu Groups plugin <= 0.1.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:57.794Z

Reserved: 2025-05-30T14:04:14.280Z

Link: CVE-2025-49035

cve-icon Vulnrichment

Updated: 2025-08-27T16:10:36.054Z

cve-icon NVD

Status : Deferred

Published: 2025-08-27T04:15:57.260

Modified: 2026-04-23T15:31:12.157

Link: CVE-2025-49035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T08:15:32Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')