Nav Menu Manager

Nav Menu Manager has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Nav Menu Manager has a vendor fix available, so running the current release closes it.

All of these findings were reported by Muhammad Yudha - DJ. Nav Menu Manager is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Nav Menu Manager vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-31017

Nav Menu Manager <= 3.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Nav Menu Manager banner
Latestv3.2.7.1

Nav Menu Manager

Robert Noakes

Author

Robert Noakes

5.0(5)
100/100
Last Updated
2025-10-25 (11mo ago)
Active Installs
800+
Downloads
38,129
Requires WP
5.0+
Requires PHP
0+
Tested up to
WP 6.8.8
Created
2016-07-14 (10y ago)

Simplifies nav menu maintenance and functionality providing more control over nav menus with less coding. Nav Menus Easily register nav menus via the WordPress admin Fail-safe code helps add a layer of protection to the theme Disable already registered nav menus that won’t be used on the site wp_nav_menu and shortcode generator for quick theme and content implementation Improved nav menu sidebar widget for better widgetized menus Nav Menu Items Add a global active class for all active nav menu items Exclude default ID attributes from all nav menu items Custom fields on nav menu items for ID, query string and/or hash For collapse/expand functionality, install Nav Menu Collapse View the Knowledge Base »

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C