
CVE-2026-1755 The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_wp_attachment_image_alt’ post meta in all versions up to, and in… https://www.cve.org/CVERecord?id=CVE-2026-1755
Post summary
The Menu Icons plugin for WordPress contains a stored XSS flaw through the ‘_wp_attachment_image_alt’ post meta field.

