WP Edit Menu <= 1.5.0 - Cross-Site Request Forgery
high
The WP Edit Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.0. This is due to missing or incorrect nonce validation on the wpem_remove_menu_entry function. This makes it possible for unauthenticated attackers to delete posts or pages, via forged request grante...
- CVSS:
- 8.8
- Affected:
- up to 1.5.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 1, 2022
CVE-2022-2275 on NVD →
WP Edit Menu < 1.5.0 - Missing Authorization to Post Deletion
high
The WP Edit Menu plugin for WordPress lacks authorization checks on one of its ajax action and is vulnerable to Arbitrary Post Deletion in versions below 1.5.0. This is due to a missing capability check in the function wpem_remove_menu_entry. This makes it possible for an unauthenticated attacker to delete posts and pa...
- CVSS:
- 7.5
- Affected:
- up to 1.5.0
- Fixed in:
- 1.5.0
- Disclosed:
- Aug 1, 2022
CVE-2022-2276 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database