plugin

Advance Menu Manager Vulnerabilities

23 known security issues reported for the Advance Menu Manager WordPress plugin. Most recent disclosed Dec 18, 2024.

1 high 6 medium

Running Advance Menu Manager on your site? Check whether your installed version is affected.

Scan your site free

Advance Menu Manager [advance-menu-manager] < 3.1.2

unknown

[en] Missing Authorization vulnerability in theDotstore Advance Menu Manager.This issue affects Advance Menu Manager: from n/a through 3.1.1.

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Dec 18, 2024

CVE-2024-54381 on NVD →

Advance Menu Manager <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Settings Change

medium

The Advance Menu Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
Dec 11, 2024

CVE-2024-54381 on NVD →

Advance Menu Manager [advance-menu-manager] < 3.0.2

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Advance Menu Manager [advance-menu-manager] < 3.0.7

unknown

Update the WordPress Advance Menu Manager plugin to the latest available version (at least 3.0.7). WordFence discovered and reported this Broken Access Control vulnerability in WordPress Advance Menu Manager Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in...

Affected:
up to 3.0.7
Fixed in:
3.0.7
Disclosed:
Nov 3, 2023

Advance Menu Manager [advance-menu-manager] < 3.0.7

unknown

Update the WordPress Advance Menu Manager plugin to the latest available version (at least 3.0.7). WordFence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Advance Menu Manager Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted acti...

Affected:
up to 3.0.7
Fixed in:
3.0.7
Disclosed:
Nov 3, 2023

Advance Menu Manager <= 3.0.6 - Missing Authorization

medium

The Advance Menu Manager plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the dsamm_action_ajax_for_delete_menu(), dsamm_amm_duplicate_menu(), and dsamm_action_ajax_for_create_menu() functions in all versions up to, and including, 3.0.6. This makes it possible...

CVSS:
4.3
Affected:
up to 3.0.6
Fixed in:
3.0.7
Disclosed:
Nov 2, 2023

Advance Menu Manager <= 3.0.6 - Cross-Site Request Forgery

medium

The Advance Menu Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.6. This is due to missing or incorrect nonce validation on the dsamm_action_ajax_for_delete_menu(), dsamm_amm_duplicate_menu(), and dsamm_action_ajax_for_create_menu() functions. This make...

CVSS:
4.3
Affected:
up to 3.0.6
Fixed in:
3.0.7
Disclosed:
Nov 2, 2023

Advance Menu Manager [advance-menu-manager] < 3.0.7

unknown

The Advance Menu Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.6. This is due to missing or incorrect nonce validation on the dsamm_action_ajax_for_delete_menu(), dsamm_amm_duplicate_menu(), and dsamm_action_ajax_for_create_menu() functions. This make...

Affected:
up to 3.0.7
Fixed in:
3.0.7
Disclosed:
Nov 2, 2023

Advance Menu Manager [advance-menu-manager] < 3.0.7

unknown

The Advance Menu Manager plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the dsamm_action_ajax_for_delete_menu(), dsamm_amm_duplicate_menu(), and dsamm_action_ajax_for_create_menu() functions in all versions up to, and including, 3.0.6. This makes it possible...

Affected:
up to 3.0.7
Fixed in:
3.0.7
Disclosed:
Nov 2, 2023

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
3.0.1 – 3.0.5
Fixed in:
3.0.6
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Advance Menu Manager [advance-menu-manager] < 3.0.2

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
Mar 4, 2022

Advance Menu Manager [advance-menu-manager] < 3.0.2

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress Advance Menu Manager plugin (versions <= 3.0.1).

Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
Feb 28, 2022

Advance Menu Manager [advance-menu-manager] < 3.0.2

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Advance Menu Manager plugin (versions <= 3.0.1).

Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
Feb 28, 2022

Advanced Menu Manager <= 2.9.6 - Cross-Site Request Forgery to Menu Edition

high

The Advanced Menu Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.6. This is due to missing or incorrect nonce validation on the 'amm_save_existing_menu' function. This makes it possible for unauthenticated attackers to edit the vulnerable services menu via...

CVSS:
8.8
Affected:
up to 2.9.6
Fixed in:
3.0
Disclosed:
Jul 12, 2021

Advanced Menu Manager <= 3.0.6 - Authenticated (Subscriber+) Menu Creation/Deletion

medium

The Advanced Menu Manager plugin for WordPress is vulnerable to Arbitrary Menu Creation/Deletion in versions up to, and including, 3.0.6. This is due to missing capability and nonce checks in its 'my_action_delete_menu' and 'my_action_create_menu_ajax' AJAX actions. This makes it possible for authenticated attackers (u...

CVSS:
5.4
Affected:
up to 3.0.6
Fixed in:
3.0.7
Disclosed:
Jul 12, 2021

Advance Menu Manager [advance-menu-manager] < 3.0

unknown

The Advanced Menu Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.6. This is due to missing or incorrect nonce validation on the 'amm_save_existing_menu' function. This makes it possible for unauthenticated attackers to edit the vulnerable services menu via...

Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Jul 12, 2021

Advance Menu Manager [advance-menu-manager] < 3.0.7

unknown

The Advanced Menu Manager plugin for WordPress is vulnerable to Arbitrary Menu Creation/Deletion in versions up to, and including, 3.0.6. This is due to missing capability and nonce checks in its 'my_action_delete_menu' and 'my_action_create_menu_ajax' AJAX actions. This makes it possible for authenticated attackers (u...

Affected:
up to 3.0.7
Fixed in:
3.0.7
Disclosed:
Jul 12, 2021

Advance Menu Manager [advance-menu-manager] < 3.0

unknown

Unauthorized Menu Edition via Cross-Site Request Forgery (CSRF) vulnerability discovered by WPScanteam in WordPress Advance Menu Manager plugin (versions <= 2.9.6).

Affected:
up to 3.0
Fixed in:
3.0
Disclosed:
Jul 12, 2021

Advance Menu Manager [advance-menu-manager] < 3.0.2

unknown

Unauthorized Menu Creation/Deletion vulnerability discovered by WPScanTeam in WordPress Advance Menu Manager plugin (versions <= 3.0.1)

Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
Jul 12, 2021

Advance Menu Manager [advance-menu-manager] <= 3.0.4

unknown

The plugin is lacking any capability and CSRF checks in its my_action_delete_menu and my_action_create_menu_ajax AJAX actions, allowing any authenticated users (such as subscriber) to call them. Such attack could also be performed via a CSRF vector against any logged in user.

Affected:
up to 3.0.4
Fixed in:
3.0.4

Advance Menu Manager [advance-menu-manager] < 3.0.6

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 3.0.6
Fixed in:
3.0.6

CVE-2023-33999 on NVD →

Advance Menu Manager [advance-menu-manager] < 3.0

unknown

The plugin does not properly check for CSRF in its amm_save_existing_menu function, allowing attackers to make logged in high privilege users edit menus via a CSRF attack

Affected:
up to 3.0
Fixed in:
3.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database