CVE-2026-1910 | UpMenu Plugin up to 3.1 on WordPress Shortcode upmenu-menu lang cross site scripting
A vulnerability was found in UpMenu Plugin up to 3.1 on WordPress. It has been rated as problematic. This vulnerability affects the function upmenu-menu of the component Shortcode Handler. Performing a manipulation of the argument lang results in cross site scripting.
This vulnerability is known as CVE-2026-1910. Remote exploitation of the attack is possible. No exploit is available.