CVE-2026-83532 PUBLISHED

Custom Menu Wizard <= 3.3.1 - Contributor+ Stored XSS via Shortcode Attributes

Assigner: WPScan
Reserved: 31.08.2026 Published: 12.09.2026 Updated: 12.09.2026

The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.

Product Status

Vendor Unknown
Product Custom Menu Wizard Widget
Versions Default: unknown
  • affected from 0 to 3.3.1 (incl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE