CyberRota Analysis
AI-GeneratedThe HT Menu WordPress plugin prior to version 1.2.7 is vulnerable due to a lack of capability checks and insufficient escaping of stored settings, enabling users with minimal permissions to inject malicious JavaScript into navigation menus. This vulnerability can lead to cross-site scripting (XSS) attacks, affecting any visitor, including administrators, who views the compromised menu. WordPress site administrators and developers using this plugin should prioritize immediate updates to mitigate potential exploitation risks.
Original NVD Description
The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permissions such as Subscribers to store JavaScript that executes in the browser of any visitor, administrators included, who views the affected menu.