ShiftNav – Responsive Mobile Menu
ShiftNav – Responsive Mobile Menu has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for ShiftNav – Responsive Mobile Menu has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. ShiftNav – Responsive Mobile Menu is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-49243ShiftNav – Responsive Mobile Menu <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

ShiftNav – Responsive Mobile Menu
Author
sevenspark
ShiftNav is an awesome mobile menu for WordPress. It looks and acts like native app off-canvas slide-out menus for popular apps like Facebook, Gmail, etc. ShiftNav Demo – see how it works Get started: ShiftNav Quick Setup Guide Feature Overview Native App-Style Menus Automatic Integration Light & Dark Skins Works with the WordPress 3 Menu System Touch-enabled CSS3 Transitions produce smooth animations on mobile devices Configurable Knowledgebase Want to take your menu to the next level? Go Pro Browser Compatibility ShiftNav will open with a slide transition with browsers that support it. For browsers that don’t fully support CSS3 transforms, the menu will fall back to non-animated open/close functionality.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C