Impact
The vulnerability is an improper neutralization of input that allows attackers to store malicious scripts in the plugin’s menu data. A stored cross‑site scripting flaw lets an attacker inject arbitrary JavaScript that runs in the browsers of people who view the affected menu, leading to credential theft, session hijacking, or defacement. The weakness corresponds to CWE‑79 and is present in all plugin versions up to and including 1.8.
Affected Systems
The affected product is the WordPress plugin ShiftNav – Responsive Mobile Menu from the vendor sevenspark. Versions 1.8 and all earlier releases are vulnerable. Users deploying this plugin on any WordPress installation without a newer fixed version are at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating a moderate risk, and the EPSS score is reported as less than 1 %, suggesting very low probability of public exploitation at the moment. The flaw is not listed in CISA’s KEV catalog. Attackers likely target the plugin through menu creation or editing interfaces that accept untrusted user input; the stored nature means the payload persists until the content is removed. Because it is client‑side, a successful exploit does not grant direct access to the server, but it can compromise any visitor to the affected site.
OpenCVE Enrichment
EUVD