Executive brief
A vulnerability exists in a WordPress plugin used to create floating navigation menus and category sidebars. An attacker with administrative or editor-level access can inject malicious scripts into the website's menu settings. These scripts will then execute in the browsers of other users who visit the site, potentially leading to unauthorized actions or data theft.
Technical details
The WPB Floating Menu & Categories for WordPress plugin (versions up to 1.0.8) contains a Stored Cross-Site Scripting (XSS) vulnerability. The flaw is located in the 'Icon CSS Class' category field within the admin/category-icon.php component, which fails to perform adequate input sanitization and output escaping. An authenticated attacker with Editor-level permissions or higher can submit malicious JavaScript into this field. This script is stored in the database and subsequently executed in the security context of any user (including administrators) who views the page where the menu or category icon is rendered. This could lead to session hijacking or unauthorized administrative actions.
Affected products
- WPB WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons Up to and including 1.0.8
Timeline
- 2026-05-21: disclosed
- 2026-05-21: advisory