CVE-2024-47365
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atakan Au Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu allows Stored XSS.This issue affects Automatically Hierarchic Categories in Menu: from n/a through <= 2.0.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in WordPress Automatically Hierarchic Categories in Menu plugin ≤2.0.5 allows authenticated attackers to inject arbitrary scripts.
The Automatically Hierarchic Categories in Menu WordPress plugin (versions 2.0.5 and earlier) suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The root cause is improper neutralization of user-supplied input during web page generation, enabling the injection of malicious scripts into pages that are later served to site visitors [1].
Exploitation requires an authenticated user with the necessary privileges (likely editor or admin) to submit crafted input via the plugin's settings or menu management interface. An attacker can trigger the stored script by having a privileged user perform an action such as clicking a malicious link or visiting a specially crafted page [1].
Successful exploitation allows an attacker to inject arbitrary JavaScript, HTML, or other payloads. This can be used to redirect visitors to malicious websites, display unwanted advertisements, or steal session cookies and perform actions on behalf of the victim. The CVSS score of 6.5 indicates a medium severity [1].
The vendor has released version 2.0.6 which fixes this vulnerability. Users are strongly advised to update to the latest version or enable auto-updates for vulnerable plugins. As a workaround, ensure that only trusted users have admin-level access and avoid clicking suspicious links [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=2.0.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.