
CVE-2026-1910 The UpMenu – Online ordering for restaurants plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lang' attribute of the 'upmenu-menu' shortcode i… https://www.cve.org/CVERecord?id=CVE-2026-1910
Post summary
A stored XSS vulnerability in the UpMenu WordPress plugin was disclosed via its 'lang' attribute in the 'upmenu-menu' shortcode, but no PoC, exploitation evidence, patch, or mitigation is provided.

