Unrated severityNVD Advisory· Published Sep 30, 2026
CVE-2026-91832
CVE-2026-91832
Description
The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.9
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.