plugin

Wp Edit Menu Vulnerabilities

2 known security issues reported for the Wp Edit Menu WordPress plugin. Most recent disclosed Aug 1, 2022.

2 high

Running Wp Edit Menu on your site? Check whether your installed version is affected.

Scan your site free

WP Edit Menu <= 1.5.0 - Cross-Site Request Forgery

high

The WP Edit Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.0. This is due to missing or incorrect nonce validation on the wpem_remove_menu_entry function. This makes it possible for unauthenticated attackers to delete posts or pages, via forged request grante...

CVSS:
8.8
Affected:
up to 1.5.0
Fix:
No patched version reported
Disclosed:
Aug 1, 2022

CVE-2022-2275 on NVD →

WP Edit Menu < 1.5.0 - Missing Authorization to Post Deletion

high

The WP Edit Menu plugin for WordPress lacks authorization checks on one of its ajax action and is vulnerable to Arbitrary Post Deletion in versions below 1.5.0. This is due to a missing capability check in the function wpem_remove_menu_entry. This makes it possible for an unauthenticated attacker to delete posts and pa...

CVSS:
7.5
Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Aug 1, 2022

CVE-2022-2276 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database