Description
WordPress Plugin Menu Image is prone to an issue which allows the add-on of malicious scripts to the affected website, through the use of notice.php file. WordPress Plugin Menu Image version 2.6.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7.0 or latest
References
Related Vulnerabilities
WordPress Plugin Ultimate Member-User Profile, Registration, Login, Member Directory, Content Restriction & Membership Cross-Site Scripting (1.2.3)
OpenSSL Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2021-4044)
WordPress Plugin Spider Calendar Cross-Site Scripting (1.1.0)
Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3225)
WordPress Plugin Post SMTP-WP SMTP with Email Logs & Mobile App for Failure Alerts-Any SMTP Plus Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES, Postmark Cross-Site Scripting (2.8.6)