plugin

Mega Main Menu Vulnerabilities

5 known security issues reported for the Mega Main Menu WordPress plugin. Most recent disclosed Mar 29, 2023.

2 medium

Running Mega Main Menu on your site? Check whether your installed version is affected.

Scan your site free

Mega Main Menu <= 2.2.2 - Authenticated (Administrator+) Cross-Site Scripting

medium

The Mega Main Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,...

CVSS:
5.5
Affected:
up to 2.2.2
Fix:
No patched version reported
Disclosed:
Mar 29, 2023

CVE-2023-1575 on NVD →

Mega Main Menu [mega_main_menu] <= 2.2.2 (unfixed)

unknown

[en] The Mega Main Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a...

Affected:
up to 2.2.2
Fix:
No patched version reported
Disclosed:
Mar 29, 2023

CVE-2023-1575 on NVD →

Mega Main Menu [mega_main_menu] <= 2.2.2 (unfixed)

unknown

No patched version available. indoushka discovered and reported this Sensitive Data Exposure vulnerability in WordPress Mega Main Menu Plugin. This vulnerability has not been known to be fixed yet.

Affected:
up to 2.2.2
Fix:
No patched version reported
Disclosed:
Jan 12, 2023

Mega Main Menu <= 2.2.2 - Information Disclosure

medium

The Mega Main Menu plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.2.2. This could allow unauthenticated attackers to download configuration data such as plugin settings.

CVSS:
5.3
Affected:
up to 2.2.2
Fix:
No patched version reported
Disclosed:
Jan 10, 2023

Mega Main Menu [mega_main_menu] <= 2.2.2 (unfixed)

unknown

The Mega Main Menu plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.2.2. This could allow unauthenticated attackers to download configuration data such as plugin settings.

Affected:
up to 2.2.2
Fix:
No patched version reported
Disclosed:
Jan 10, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database