WordPress · Advance Nav Menu Manager · CVE-2026-8688
**Name of the Vulnerable Software and Affected Versions**
Advance Nav Menu Manager versions prior to 1.4
**Description**
The Advance Nav Menu Manager plugin for WordPress contains an authorization bypass. The issue occurs because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with subscriber-level access or higher can exploit this to duplicate, copy, move, or publish `nav menu item` posts. This is achieved through the `anmm save menu data` AJAX action and the `wp insert post()` function, allowing unauthorized modification of the site navigation menus.
**Recommendations**
Update Advance Nav Menu Manager to a version newer than 1.3.