Impact
The WordPress plugin WP Mobile Menu accepts an import of settings without properly verifying the nonce token, allowing an attacker to submit a cross‑site request while an administrator is logged in. The imported settings are then rendered unescaped to every site visitor, creating a stored cross‑site scripting vulnerability. An attacker who exploits this flaw can inject arbitrary JavaScript, potentially hijacking user sessions, stealing credentials, or defacing the site.
Affected Systems
This flaw applies to WP Mobile Menu plugin versions 2.7.4 through 2.8.8 and all other releases before the 2.9 stability threshold. Any WordPress installation that has these plugin versions installed and whose administrators allow the import feature to be accessed is vulnerable, regardless of the site’s overall configuration.
Risk and Exploitability
While the EPSS score and KEV status are currently not available, the CVSS-based severity is high due to the stored XSS nature. The attack vector requires an authenticated administrator session and the ability to send a crafted request; attackers can trigger the flaw by simply visiting a crafted URL, making exploitation highly feasible for anyone with access to the administrative credentials. The vulnerability remains in use because no official fix is listed in the CNA data sources, meaning that affected systems are left exposed until remediation steps are taken.
OpenCVE Enrichment