Export Import Menus <= 1.9.2 - Unauthenticated Information Exposure
medium
The Export Import Menus plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.9.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.9.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 6, 2026
CVE-2026-66684 on NVD →
Export Import Menus [export-import-menus] < 1.9.2
unknown
[en] The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dsp_export_import_menus() function in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to export menu data and settings.
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
- Disclosed:
- Jan 7, 2025
CVE-2024-10866 on NVD →
Export Import Menus <= 1.9.1 - Missing Authorization to Unauthenticated Menu Export
medium
The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dsp_export_import_menus() function in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to export menu data and settings.
- CVSS:
- 5.3
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.2
- Disclosed:
- Jan 6, 2025
CVE-2024-10866 on NVD →
Export Import Menus [export-import-menus] < 1.9.0
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Akshay Menariya Export Import Menus.This issue affects Export Import Menus: from n/a through 1.8.0.
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.0
- Disclosed:
- Dec 20, 2023
CVE-2023-34385 on NVD →
Export Import Menus <= 1.8.0 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Export Import Menus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadMenusJson() function in versions up to, and including, 1.8.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to upload arbitrary files o...
- CVSS:
- 8.8
- Affected:
- up to 1.8.0
- Fixed in:
- 1.9.0
- Disclosed:
- Sep 4, 2023
CVE-2023-34385 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database