WordPress security by component
Custom Menu Wizard Widget
Custom Menu Wizard Widget (custom-menu-wizard-widget) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 6.8.
Plugin slug:
custom-menu-wizard-widgetLatest vulnerability
CVE-2026-83532: Custom Menu Wizard Widget shortcode attributes permit stored XSS
Custom Menu Wizard Widget through 3.3.1 renders several shortcode attributes into HTML without sufficient sanitization or escaping. A contributor or higher role can store JavaScript that executes when affected content is viewed. The authoritative export does not identify the shortcode attributes or their output contexts.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-83532
Custom Menu Wizard Widget shortcode attributes permit stored XSS
Custom Menu Wizard Widget through 3.3.1 renders several shortcode attributes into HTML without sufficient sanitization or escaping. A contributor or higher role can store JavaScript that executes when affected content is viewed. The authoritative export does not identify the shortcode attributes or their output contexts.
|
See mitigation notes |
CVE6.8
NVDPending
|