Side Menu Lite <= 5.3.1 - Cross-Site Request Forgery to Settings Update
medium
The Side Menu Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can tric...
- CVSS:
- 4.3
- Affected:
- up to 5.3.1
- Fixed in:
- 5.3.2
- Disclosed:
- Jan 24, 2025
CVE-2025-24724 on NVD →
Side Menu Lite – add sticky fixed buttons <= 4.2 - Cross-Site Request Forgery
medium
The Side Menu Lite – add sticky fixed buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to missing or incorrect nonce validation on the side-menu-lite function. This makes it possible for unauthenticated attackers to delete items in bulk via...
- CVSS:
- 4.3
- Affected:
- up to 4.2
- Fixed in:
- 4.2.1
- Disclosed:
- Apr 11, 2024
CVE-2024-3476 on NVD →
Multiple Wow-Company Plugins (Various Versions) -- Reflected Cross-Site Scripting via 'page' parameter
medium
Several plugins by Wow-Company are vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri...
- CVSS:
- 6.1
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- May 22, 2023
CVE-2023-2362 on NVD →
Side Menu Lite <= 4.0 - Cross-Site Request Forgery to Item Deletion
medium
The Side Menu Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0. This is due to missing or incorrect nonce validation in the 'admin/page-main.php' file. This makes it possible for unauthenticated attackers to delete menu items via a forged request, granted they...
- CVSS:
- 4.3
- Affected:
- up to 4.0
- Fixed in:
- 4.0.1
- Disclosed:
- Mar 8, 2023
CVE-2023-27418 on NVD →
Side Menu Lite - add sticky fixed buttons < 2.2.6 - SQL Injection
high
The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue.
- CVSS:
- 8.8
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.6
- Disclosed:
- Jul 27, 2021
CVE-2021-24580 on NVD →
Side Menu Lite <= 2.2 - SQL Injection
high
The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack.
- CVSS:
- 7.2
- Affected:
- up to 2.1.1
- Fixed in:
- 2.2.1
- Disclosed:
- Jun 28, 2021
CVE-2021-24521 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database