CVE-2026-84935
—Stored XSS via Missing Capability Check in HT Menu WordPress Plugin
CVE-2026-84935 is a stored cross-site scripting (XSS) flaw in the HT Menu WordPress plugin, caused by the plugin failing to perform any capability or object-ownership check when navigation menu-item settings are saved and failing to escape those stored settings when the menu is rendered. As a result, any user with minimal permissions — as low as a Subscriber — can save JavaScript into menu-item settings, and that script executes in the browser of every visitor who views a page containing the affected menu, administrators included. An attacker whose injected script runs in an administrator's browser can steal session cookies or perform privileged actions, potentially leading to full site compromise. All WordPress sites running HT Menu before version 1.2.7 are affected, with the highest risk on sites that permit open user registration. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Update HT Menu to version 1.2.7 or later. Until patched, restrict which roles can save navigation menu-item settings and audit existing menu items for unexpected HTML or JavaScript; sites with open user registration should prioritize the update.
| HT Menu (WordPress plugin) | before 1.2.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permissions such as Subscribers to store JavaScript that executes in the browser of any visitor, administrators included, who views the affected menu.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.