Stored Cross-Site Scripting Vulnerability in Menu Icons Plugin by ThemeIsle
CVE-2026-1755

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 February 2026

What is CVE-2026-1755?

The Menu Icons plugin for WordPress, developed by ThemeIsle, exhibits a serious vulnerability that allows stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping in the '_wp_attachment_image_alt' post meta field. This flaw permits authenticated users with Author-level access or higher to inject malicious web scripts into pages. When these compromised pages are accessed by users, the injected scripts execute, potentially compromising user data and the site's integrity.

Affected Version(s)

Menu Icons by ThemeIsle 0 <= 0.13.20

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lukasz Sobanski
.