CVE-2026-91832 PUBLISHED

WP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRF

Assigner: WPScan
Reserved: 15.09.2026 Published: 30.09.2026 Updated: 30.09.2026

The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.

Product Status

Vendor Unknown
Product WP Mobile Menu
Versions Default: unaffected
  • affected from 2.7.4 to 2.9 (excl.)

Credits

  • Het Kalariya finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE
  • CWE-352 Cross-Site Request Forgery (CSRF) CWE