CVE-2026-8688
Received Received - Intake
Authorization Bypass in Advance Nav Menu Manager WordPress Plugin

Publication date: 2026-06-24

Last updated on: 2026-06-24

Assigner: Wordfence

Description
The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to duplicate, copy, move, or publish nav_menu_item posts via wp_insert_post(), modifying the site's navigation menus without authorization.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-24
Last Modified
2026-06-24
Generated
2026-06-24
AI Q&A
2026-06-24
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
advance_nav_menu_manager advance_nav_menu_manager to 1.3 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The Advance Nav Menu Manager plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 1.3. This means the plugin does not properly check if a user is authorized to perform certain actions.

As a result, authenticated users with subscriber-level access or higher can duplicate, copy, move, or publish navigation menu items without proper permission by exploiting the wp_insert_post() function.

Impact Analysis

This vulnerability allows unauthorized modification of a website's navigation menus by users who should not have such privileges.

  • Attackers with subscriber-level access can duplicate, copy, move, or publish nav_menu_item posts.
  • This can lead to unauthorized changes in site navigation, potentially confusing users or redirecting them to malicious content.
  • It may undermine the integrity and trustworthiness of the website's user interface.
Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8688. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart