Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-91832

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Sep 30, 2026
Vendor unknown

Description

The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.

References