Description
WordPress Plugin Menu Image is prone to an issue which allows the add-on of malicious scripts to the affected website, through the use of notice.php file. WordPress Plugin Menu Image version 2.6.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7.0 or latest
References
Related Vulnerabilities
WordPress Plugin bbPress Cross-Site Scripting (2.5.8)
Oracle Application Server CVE-2008-2583 Vulnerability (CVE-2008-2583)
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-30179)
WordPress Plugin IMPress Listings Cross-Site Scripting (2.0.1)
WordPress Plugin WP Simple Booking Calendar SQL Injection (2.0.6)