PT-2026-1708 · WordPress · Autogen Headers Menu

Youcef Hamdani

·

Published

2026-01-09

·

Updated

2026-01-09

·

CVE-2025-13704

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Autogen Headers Menu plugin for WordPress versions up to and including 1.0.1
Description The Autogen Headers Menu plugin for WordPress is susceptible to Stored Cross-Site Scripting through the head class parameter of the autogen menu shortcode. Insufficient input sanitization and output escaping allow authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into pages. These scripts will execute when a user accesses the injected page. The vulnerable parameter is head class within the autogen menu shortcode.
Recommendations Versions prior to and including 1.0.1 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-13704

Affected Products

Autogen Headers Menu