PLUGIN SECURITY

Is Mobile Menu safe?

Need some help with the mobile website experience? Need an Mobile Menu plugin that keep your mobile visitors engaged?

What this plugin does

  • Slug: mobile-menu
  • Author: Rui Guerreiro
  • 70000+ active installs
  • 94/100 rating (256 reviews on wordpress.org)
  • 2313746 all-time downloads
  • On WordPress.org since 2014-02-03

menumobilemobile menuresponsiveresponsive menu

Maintenance status

  • Latest known version: 2.8.8
  • Last updated: 2025-06-23 6:57am GMT
  • Tested up to WordPress: 6.8.8
  • Requires PHP: 5.6+

Known vulnerabilities

6 known CVEs on file for Mobile Menu. Reported between 2019 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13362 WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.8.7 2.8.7 2026-04-30 ✓ fixed in latest
CVE-2024-2508 WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.5 Missing Authorization Medium 5.3 < 2.8.5 2.8.5 2024-07-30 ✓ fixed in latest
CVE-2024-37274 WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.4.4 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.8.4.4 2.8.4.4 2024-06-27 ✓ fixed in latest
CVE-2024-3987 WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.4.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.8.4.3 2.8.4.3 2024-06-06 ✓ fixed in latest
CVE-2023-33999 WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 2.8.4 2.8.4 2023-07-18 ✓ fixed in latest
WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.2.7 Missing Authorization Medium 6.3 < 2.8.2.7 2.8.2.7 2022-03-04 ✓ fixed in latest
WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.2.7 Unknown < 2.8.2.7 2.8.2.7 2022-02-28 ✓ fixed in latest
WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.2.7 Unknown < 2.8.2.7 2.8.2.7 2022-02-28 ✓ fixed in latest
+ 7 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24435 WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.2.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.8.2.3 2.8.2.3 2021-08-09 ✓ fixed in latest
WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.2.3 Unknown < 2.8.2.3 2.8.2.3 2021-08-09 ✓ fixed in latest
WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.7.3 Unknown < 2.7.3 2.7.3 2019-03-02 ✓ fixed in latest
WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.7.3 Unknown < 2.7.3 2.7.3 2019-02-25 ✓ fixed in latest
WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.7.3 Unknown < 2.7.3 2.7.3 ✓ fixed in latest
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update Unknown < 2.7.3 2.7.3 ✓ fixed in latest
Unauthorised AJAX Calls via Freemius Unknown < 2.8.2.7 2.8.2.7 ✓ fixed in latest

How to fix it

Keep Mobile Menu updated — 2.8.8 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

  • AMP — 400000+ active installs — 76/100 (367) — max PHP 8.4
  • Admin Menu Editor — 300000+ active installs — 92/100 (312) — max PHP 8.4
  • Max Mega Menu — 300000+ active installs — 96/100 (877) — max PHP 8.4
  • Menu Image, Icons made easy — 100000+ active installs — 90/100 (123) — max PHP 8.4
  • Duplicate Menu — 100000+ active installs — 92/100 (104) — max PHP 8.4

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.