Name of the Vulnerable Software and Affected Versions:
Admin Menu Editor plugin for WordPress versions prior to 1.15
Description:
The Admin Menu Editor plugin for WordPress is susceptible to Stored Cross-Site Scripting via the `placeholder` parameter due to insufficient input sanitization and output escaping. This allows authenticated attackers with Author-level access or higher to inject arbitrary web scripts into pages. These scripts will execute when a user accesses the injected page.
Recommendations:
Update the Admin Menu Editor plugin to version 1.15 or later.