Description
The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.
Published: 2026-09-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via CSRF
Action: Immediate Patch
AI Analysis

Impact

The WordPress plugin WP Mobile Menu accepts an import of settings without properly verifying the nonce token, allowing an attacker to submit a cross‑site request while an administrator is logged in. The imported settings are then rendered unescaped to every site visitor, creating a stored cross‑site scripting vulnerability. An attacker who exploits this flaw can inject arbitrary JavaScript, potentially hijacking user sessions, stealing credentials, or defacing the site.

Affected Systems

This flaw applies to WP Mobile Menu plugin versions 2.7.4 through 2.8.8 and all other releases before the 2.9 stability threshold. Any WordPress installation that has these plugin versions installed and whose administrators allow the import feature to be accessed is vulnerable, regardless of the site’s overall configuration.

Risk and Exploitability

While the EPSS score and KEV status are currently not available, the CVSS-based severity is high due to the stored XSS nature. The attack vector requires an authenticated administrator session and the ability to send a crafted request; attackers can trigger the flaw by simply visiting a crafted URL, making exploitation highly feasible for anyone with access to the administrative credentials. The vulnerability remains in use because no official fix is listed in the CNA data sources, meaning that affected systems are left exposed until remediation steps are taken.

Generated by OpenCVE AI on September 30, 2026 at 12:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update WP Mobile Menu to the latest release (2.9 or later) where the nonce check and output escaping are fixed.
  • If an upgrade is not possible immediately, disable or remove the WP Mobile Menu plugin to prevent the import path from being used.
  • After disabling the plugin, inspect the site’s database for any inserted malicious scripts that may have been stored via the compromised import feature and clean them manually.
  • Consider restricting administrative access to known IP addresses or enabling two‑factor authentication to reduce the likelihood of an attacker gaining sufficient credentials to trigger the flaw.

Generated by OpenCVE AI on September 30, 2026 at 12:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.
Title WP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRF
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-30T13:37:21.907Z

Reserved: 2026-09-15T08:18:56.191Z

Link: CVE-2026-91832

cve-icon Vulnrichment

Updated: 2026-09-30T13:21:52.661Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T06:17:09.593

Modified: 2026-09-30T16:28:31.510

Link: CVE-2026-91832

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')