wp_kses_post of the component Navigation Menu Widget. Such manipulation of the argument data-toggle-icon/data-close-icon leads to cross site scripting.
This vulnerability is traded as CVE-2026-15787. The attack may be launched remotely. There is no exploit available.
Intelligence View
SOCIAL SHARE CARD GENERATOR