plugin

Side Menu Lite Vulnerabilities

6 known security issues reported for the Side Menu Lite WordPress plugin. Most recent disclosed Jan 24, 2025.

2 high 4 medium

Running Side Menu Lite on your site? Check whether your installed version is affected.

Scan your site free

Side Menu Lite <= 5.3.1 - Cross-Site Request Forgery to Settings Update

medium

The Side Menu Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can tric...

CVSS:
4.3
Affected:
up to 5.3.1
Fixed in:
5.3.2
Disclosed:
Jan 24, 2025

CVE-2025-24724 on NVD →

Side Menu Lite – add sticky fixed buttons <= 4.2 - Cross-Site Request Forgery

medium

The Side Menu Lite – add sticky fixed buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to missing or incorrect nonce validation on the side-menu-lite function. This makes it possible for unauthenticated attackers to delete items in bulk via...

CVSS:
4.3
Affected:
up to 4.2
Fixed in:
4.2.1
Disclosed:
Apr 11, 2024

CVE-2024-3476 on NVD →

Multiple Wow-Company Plugins (Various Versions) -- Reflected Cross-Site Scripting via 'page' parameter

medium

Several plugins by Wow-Company are vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri...

CVSS:
6.1
Affected:
up to 4.0.1
Fixed in:
4.0.2
Disclosed:
May 22, 2023

CVE-2023-2362 on NVD →

Side Menu Lite <= 4.0 - Cross-Site Request Forgery to Item Deletion

medium

The Side Menu Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0. This is due to missing or incorrect nonce validation in the 'admin/page-main.php' file. This makes it possible for unauthenticated attackers to delete menu items via a forged request, granted they...

CVSS:
4.3
Affected:
up to 4.0
Fixed in:
4.0.1
Disclosed:
Mar 8, 2023

CVE-2023-27418 on NVD →

Side Menu Lite - add sticky fixed buttons < 2.2.6 - SQL Injection

high

The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue.

CVSS:
8.8
Affected:
up to 2.2.6
Fixed in:
2.2.6
Disclosed:
Jul 27, 2021

CVE-2021-24580 on NVD →

Side Menu Lite <= 2.2 - SQL Injection

high

The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack.

CVSS:
7.2
Affected:
up to 2.1.1
Fixed in:
2.2.1
Disclosed:
Jun 28, 2021

CVE-2021-24521 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database