Menubar <= 5.8.2 - Cross-Site Request Forgery in wpm-admin.php
medium
The Menubar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.2. This is due to missing or incorrect nonce validation within wpm-admin.php. This makes it possible for unauthenticated attackers to delete menus or reset the menubar via a forged request granted they can...
- CVSS:
- 5.4
- Affected:
- up to 5.8.2
- Fixed in:
- 5.9
- Disclosed:
- Jul 4, 2023
CVE-2023-36687 on NVD →
Menubar <= 5.7.2 - Reflected Cross-Site Scripting
medium
The Menubar WordPress plugin before 5.8 does not sanitise and escape the command parameter before outputting it back in the response via the menubar AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting vulnerability.
- CVSS:
- 6.4
- Affected:
- up to 5.7.2
- Fixed in:
- 5.8
- Disclosed:
- Apr 9, 2022
CVE-2022-1152 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database