Executive brief
The Advance Nav Menu Manager plugin for WordPress, which helps administrators organize website navigation, contains a security flaw that allows low-level users to modify site menus. An attacker with a basic account (such as a subscriber) can move, copy, or publish menu items without permission. This could lead to unauthorized changes to the website's structure and navigation, potentially misleading visitors or disrupting the user experience.
Technical details
The Advance Nav Menu Manager plugin for WordPress (versions up to 1.3) is vulnerable to a missing authorization check (CWE-862). The plugin fails to properly verify user permissions before executing actions related to menu management. Specifically, it allows authenticated attackers with subscriber-level privileges or higher to duplicate, copy, move, or publish 'nav_menu_item' posts via the wp_insert_post() function. This enables unauthorized modification of the site's navigation menus. The vulnerability is exploitable via network requests by any authenticated user. No patch has been explicitly confirmed in the provided text, though versions up to 1.3 are listed as affected.
Affected products
- krishaweb Advance Nav Menu Manager up to, and including, 1.3
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory
References
- https://plugins.trac.wordpress.org/browser/advance-nav-menu-manager/tags/1.1/include/class-advancenavmenumanager.php
- https://plugins.trac.wordpress.org/browser/advance-nav-menu-manager/tags/1.1/include/class-advancenavmenumanager.php
- https://plugins.trac.wordpress.org/browser/advance-nav-menu-manager/tags/1.1/include/option.php
- https://plugins.trac.wordpress.org/browser/advance-nav-menu-manager/tags/1.3/include/class-advancenavmenumanager.php
- https://plugins.trac.wordpress.org/browser/advance-nav-menu-manager/tags/1.3/include/class-advancenavmenumanager.php
- https://plugins.trac.wordpress.org/browser/advance-nav-menu-manager/tags/1.3/include/option.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e234a79d-5d46-44db-833c-51e202dc49bf?source=cve