Impact
The Custom Menu Wizard Widget plugin for WordPress versions up to 3.3.1 fails to escape several shortcode attributes before rendering them as HTML, creating a stored cross‑site scripting vulnerability (CWE‑79). An attacker who has contributor‑level access or higher can insert malicious JavaScript into content and runs in the browsers of every visitor who loads the affected menu shortcode.
Affected Systems
WordPress sites that have the Custom Menu Wizard Widget plugin installed at version 3.3.1 or earlier. Any installation where users with contributor or higher attributes is susceptible. The plugin is identified only as Custom Menu Wizard Widget, indicating it is a WordPress widget or plugin.
Risk and Exploitability
The vulnerability requires the attacker to possess contributor or higher role on the target site. Once until the plugin is updated or the offending shortcode is removed. The CVSS score of 6.8 places it in the medium‑to‑high severity range, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been observed yet.
OpenCVE Enrichment