PLUGIN SECURITY

Is JetMenu safe?

Connect Polylang with Elementor: translated templates, language switcher widget, language visibility conditions and more

What this plugin does

  • Slug: jet-menu
  • Author: David Decker
  • 100000+ active installs
  • 96/100 rating (51 reviews on wordpress.org)
  • 2124970 all-time downloads
  • On WordPress.org since 2018-11-28

dynamic tagselementorlanguage switchermultilingualpolylang

Maintenance status

  • Latest known version: 7.9
  • Last updated: 2025-12-31 9:49am GMT
  • Tested up to WordPress: 6.9.7
  • Requires PHP: 5.6+

Known vulnerabilities

5 known CVEs on file for JetMenu. Reported between 2023 and 2025.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-53987 JetMenu [jet-menu] < 2.4.11.2 Insertion of Sensitive Information Into Sent Data Medium 6.5 < 2.4.11.2 2.4.11.2 2025-07-16 ✓ fixed in latest
CVE-2025-26953 JetMenu [jet-menu] < 2.4.9.1 Missing Authorization High 7.5 < 2.4.9.1 2.4.9.1 2025-04-15 ✓ fixed in latest
CVE-2023-48762 JetMenu [jet-menu] < 2.4.2 Cross-Site Request Forgery (CSRF) Medium 6.3 < 2.4.2 2.4.2 2023-11-28 ✓ fixed in latest
CVE-2023-48761 JetMenu [jet-menu] < 2.4.2 Missing Authorization Medium 6.3 < 2.4.2 2.4.2 2023-11-28 ✓ fixed in latest
CVE-2023-48760 JetMenu [jet-menu] < 2.4.2 Missing Authorization High 8.2 < 2.4.2 2.4.2 2023-11-28 ✓ fixed in latest

How to fix it

Keep JetMenu updated — 7.9 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.