---
id: CVE-2026-84935
title: >-
  The HT Menu  WordPress plugin before 1.2.7 does not perform any capability or
  object-ownership check when saving navigation menu-item settings, and does not
  escape those stored settings when the menu is rendered, allowing users with
  mini…
summary: >-
  The HT Menu  WordPress plugin before 1.2.7 does not perform any capability or
  object-ownership check when saving navigation menu-item settings, and does not
  escape those stored settings when the menu is rendered, allowing users with
  mini…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
published: '2026-09-05'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:15:18.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84935'
references:
  - url: 'https://wpscan.com/vulnerability/10aeb456-764d-4f4d-a2c9-e357474d59c7/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00413
epssPercentile: 0.32849
ingestedAt: '2026-09-06T11:54:30.388Z'
---

## Overview

The HT Menu  WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permissions such as Subscribers to store JavaScript that executes in the browser of any visitor, administrators included, who views the affected menu.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
