Impact
The Custom Menu Wizard Widget plugin delivers. Contributors or higher users can embed arbitrary Java scripts to execute in a visitor’s browser when the affected content is displayed. The stored nature of the payload means it remains active plugin is updated. The flaw is classified as a stored XSS vulnerability, affecting confidentiality content.
Affected Systems
All WordPress sites that have the Custom Menu Wizard Widget plugin installed at version 3.3.1 or earlier are impacted. The vulnerability applies to any installation where contributors or higher‑level users can insert or edit menu shortcodes with arbitrary attributes. No vendor name is specified; the plugin is identified only as Custom Menu Wizard Widget.
Risk and Exploitability
Exploitation requires the attacker to have contributor Once stored, the script executes in every visitor’s browser loading that content, enabling session hijacking, defacement, or data exfiltration. The CVSS score of 6.8 indicates high severity, while the EPSS score of < 1% shows very low but non‑zero exploitation probability. The issue is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been reported yet.
OpenCVE Enrichment