SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84935

HIGH · CVSS 8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The HT Menu WordPress plugin prior to version 1.2.7 is vulnerable due to a lack of capability checks and insufficient escaping of stored settings, enabling users with minimal permissions to inject malicious JavaScript into navigation menus. This vulnerability can lead to cross-site scripting (XSS) attacks, affecting any visitor, including administrators, who views the compromised menu. WordPress site administrators and developers using this plugin should prioritize immediate updates to mitigate potential exploitation risks.

CVE
CVE-2026-84935
Severity
HIGH
CVSS
8
EPSS
0.23%
WordPress Java

Original NVD Description

The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permissions such as Subscribers to store JavaScript that executes in the browser of any visitor, administrators included, who views the affected menu.