Nazar Hotsa is correct – that vulnerability report is about a different plugin.
Sorry for not responding sooner! For some reason, I didn’t get a notification about this thread.
Hostinger hpanel was showing that alert about my Admin Menu Editor plugin and suggested immediate removal. Same thing was suggested by Wordfence Security – Firewall & Malware Scan which is reputed as far as I know. Could you please check?
I already looked into this shortly after the report first came out – a few other users contacted me about it.
The report that you mentioned has a link to the affected plugin. Scroll down to the “References” section and click the “Plugin page” link. You will see that it goes to a different plugin that just happens to have the same name.
Unfortunately, it seems that various tools just look at the plugin name and don’t bother to check the slug or even the version number. I’m afraid I don’t have the energy to convince every tool developer to update their detection algorithms.