Unrated severityNVD Advisory· Published Sep 12, 2026
CVE-2026-83532
CVE-2026-83532
Description
The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=3.3.1+ 1 more
- (no CPE)range: <=3.3.1
- (no CPE)range: <=3.3.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.