← WordPress Vulnerabilities
WordPress security by component

Custom Menu Wizard Widget

Custom Menu Wizard Widget (custom-menu-wizard-widget) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 6.8.

Plugin slug: custom-menu-wizard-widget

CVE-2026-83532: Custom Menu Wizard Widget shortcode attributes permit stored XSS

Custom Menu Wizard Widget through 3.3.1 renders several shortcode attributes into HTML without sufficient sanitization or escaping. A contributor or higher role can store JavaScript that executes when affected content is viewed. The authoritative export does not identify the shortcode attributes or their output contexts.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for custom-menu-wizard-widget
Safe version
Sep 12, 2026 CVE-2026-83532
Custom Menu Wizard Widget shortcode attributes permit stored XSS
Custom Menu Wizard Widget through 3.3.1 renders several shortcode attributes into HTML without sufficient sanitization or escaping. A contributor or higher role can store JavaScript that executes when affected content is viewed. The authoritative export does not identify the shortcode attributes or their output contexts.
See mitigation notes
CVE6.8
NVDPending