Junglewise Threat Intelligence

CVE-2026-66684: WordPress Export Import Menus unauthenticated sensitive data exposure

CVE-2026-66684 · Severity: medium · CVSS 5.3 · Published 2026-08-06

Vendors: Wordpress.

Executive brief

Export Import Menus is a WordPress plugin used to export and import menu structures on WordPress sites. The plugin in versions 1.9.2 and earlier exposes sensitive data without requiring authentication, allowing unauthorized visitors to access potentially private information through the export/import functionality.

Technical details

The vulnerability is a sensitive data exposure issue in the Export Import Menus WordPress plugin affecting versions 1.9.2 and earlier. The vulnerable export and import menu functions fail to enforce proper authentication checks, allowing unauthenticated attackers to access and potentially exfiltrate sensitive data via network-accessible endpoints. The vulnerability requires no user interaction and is exploitable by any remote, unauthenticated actor with network access to the affected WordPress site. An attacker can retrieve private menu data and associated information without proper authorization. No official patch is currently available as of the advisory publication date.

Affected products

  • WordPress Export Import Menus <=1.9.2

Timeline

  • 2026-08-06: disclosed: Published by Patchstack
  • 2026-07-08: other: Reported to Patchstack by Ananda Dhakal

References