Description
The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
Published: 2026-09-12
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑site XSS
Action: Patch
AI Analysis

Impact

The Custom Menu Wizard Widget plugin for WordPress versions up to 3.3.1 fails to escape several shortcode attributes before rendering them as HTML, creating a stored cross‑site scripting vulnerability (CWE‑79). An attacker who has contributor‑level access or higher can insert malicious JavaScript into content and runs in the browsers of every visitor who loads the affected menu shortcode.

Affected Systems

WordPress sites that have the Custom Menu Wizard Widget plugin installed at version 3.3.1 or earlier. Any installation where users with contributor or higher attributes is susceptible. The plugin is identified only as Custom Menu Wizard Widget, indicating it is a WordPress widget or plugin.

Risk and Exploitability

The vulnerability requires the attacker to possess contributor or higher role on the target site. Once until the plugin is updated or the offending shortcode is removed. The CVSS score of 6.8 places it in the medium‑to‑high severity range, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been observed yet.

Generated by OpenCVE AI on September 15, 2026 at 18:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Custom Menu Wizard Widget plugin to a version newer than 3.3.1 that sanitizes shortcode attributes.
  • If an upgrade is not immediately possible, delete or disable all shortcodes that contain unsanitized attributes to prevent script execution.
  • Restrict contributor or higher‑level roles from editing menu shortcodes, or implement server‑side validation and escaping of shortcode attributes to block the XSS vector.

Generated by OpenCVE AI on September 15, 2026 at 18:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
Title Custom Menu Wizard <= 3.3.1 - Contributor+ Stored XSS via Shortcode Attributes
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:36:52.962Z

Reserved: 2026-08-31T16:42:41.572Z

Link: CVE-2026-83532

cve-icon Vulnrichment

Updated: 2026-09-12T15:26:48.555Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:26.353

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-83532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')