Stored Cross-Site Scripting Vulnerability in Menu Icons Plugin by ThemeIsle
CVE-2026-1755
6.4MEDIUM
What is CVE-2026-1755?
The Menu Icons plugin for WordPress, developed by ThemeIsle, exhibits a serious vulnerability that allows stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping in the '_wp_attachment_image_alt' post meta field. This flaw permits authenticated users with Author-level access or higher to inject malicious web scripts into pages. When these compromised pages are accessed by users, the injected scripts execute, potentially compromising user data and the site's integrity.
Affected Version(s)
Menu Icons by ThemeIsle 0 <= 0.13.20