plugin

Wp Megamenu Vulnerabilities

9 known security issues reported for the Wp Megamenu WordPress plugin. Most recent disclosed Dec 13, 2024.

1 high 1 medium

Running Wp Megamenu on your site? Check whether your installed version is affected.

Scan your site free

WP Mega Menu [wp-megamenu] <= 1.4.2 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in Themeum WP Mega Menu allows Object Injection.This issue affects WP Mega Menu: from n/a through 1.4.2.

Affected:
up to 1.4.2
Fix:
No patched version reported
Disclosed:
Dec 13, 2024

CVE-2024-54282 on NVD →

WP Mega Menu <= 1.4.2 - Authenticated (Administrator+) PHP Object Injection

high

The WP Mega Menu plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerab...

CVSS:
7.2
Affected:
up to 1.4.2
Fix:
No patched version reported
Disclosed:
Dec 11, 2024

CVE-2024-54282 on NVD →

WP Mega Menu [wp-megamenu] < 1.4.0

unknown

Arbitrary Post Access vulnerability discovered by WPScanTeam in WordPress WP Mega Menu plugin (versions <= 1.3.9).

Affected:
up to 1.4.0
Fixed in:
1.4.0
Disclosed:
Sep 21, 2021

WP Mega Menu [wp-megamenu] < 1.4.1

unknown

Arbitrary Post Access vulnerability discovered by WPScanTeam in WordPress WP Mega Menu plugin (versions <= 1.4.0).

Affected:
up to 1.4.1
Fixed in:
1.4.1
Disclosed:
Sep 21, 2021

WP Mega Menu <= 1.3.6 - Unauthenticated Settings Update to Stored Cross-Site Scripting

medium

The WP Mega Menu plugin for WordPress is vulnerable to unauthenticated settings updates that can lead to stored cross-site scripting in versions up to, and including 1.3.6 due to a missing capability check and insufficient validation. This makes it possible for unauthenticated attackers to update the plugins settings a...

CVSS:
6.5
Affected:
up to 1.3.6
Fixed in:
1.3.7
Disclosed:
Apr 20, 2020

WP Mega Menu [wp-megamenu] < 1.3.7

unknown

The WP Mega Menu plugin for WordPress is vulnerable to unauthenticated settings updates that can lead to stored cross-site scripting in versions up to, and including 1.3.6 due to a missing capability check and insufficient validation. This makes it possible for unauthenticated attackers to update the plugins settings a...

Affected:
up to 1.3.7
Fixed in:
1.3.7
Disclosed:
Apr 20, 2020

WP Mega Menu [wp-megamenu] < 1.4.1

unknown

The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 1.4.1
Fixed in:
1.4.1

WP Mega Menu [wp-megamenu] < 1.4.0

unknown

The plugin does not properly check for capability and CSRF due to a logic flaw, in its export_theme() and export_wp_megamenu_nav_menu () methods, hooked to admin_init. As a result, unauthenticated users can call them and access arbitrary post data, including password protected or private ones.

Affected:
up to 1.4.0
Fixed in:
1.4.0

WP Mega Menu [wp-megamenu] < 1.4.1

unknown

The plugin does not properly check for capability and CSRF due to a logic flaw, in its export_theme() and export_wp_megamenu_nav_menu () methods, hooked as AJAX actions and available to any authenticated users. As a result, low privilege authenticated users such as subscribers can call them and access arbitrary post da...

Affected:
up to 1.4.1
Fixed in:
1.4.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database