WP Mega Menu [wp-megamenu] <= 1.4.2 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in Themeum WP Mega Menu allows Object Injection.This issue affects WP Mega Menu: from n/a through 1.4.2.
- Affected:
- up to 1.4.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 13, 2024
CVE-2024-54282 on NVD →
WP Mega Menu <= 1.4.2 - Authenticated (Administrator+) PHP Object Injection
high
The WP Mega Menu plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerab...
- CVSS:
- 7.2
- Affected:
- up to 1.4.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 11, 2024
CVE-2024-54282 on NVD →
WP Mega Menu [wp-megamenu] < 1.4.0
unknown
Arbitrary Post Access vulnerability discovered by WPScanTeam in WordPress WP Mega Menu plugin (versions <= 1.3.9).
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.0
- Disclosed:
- Sep 21, 2021
WP Mega Menu [wp-megamenu] < 1.4.1
unknown
Arbitrary Post Access vulnerability discovered by WPScanTeam in WordPress WP Mega Menu plugin (versions <= 1.4.0).
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
- Disclosed:
- Sep 21, 2021
WP Mega Menu <= 1.3.6 - Unauthenticated Settings Update to Stored Cross-Site Scripting
medium
The WP Mega Menu plugin for WordPress is vulnerable to unauthenticated settings updates that can lead to stored cross-site scripting in versions up to, and including 1.3.6 due to a missing capability check and insufficient validation. This makes it possible for unauthenticated attackers to update the plugins settings a...
- CVSS:
- 6.5
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.7
- Disclosed:
- Apr 20, 2020
WP Mega Menu [wp-megamenu] < 1.3.7
unknown
The WP Mega Menu plugin for WordPress is vulnerable to unauthenticated settings updates that can lead to stored cross-site scripting in versions up to, and including 1.3.6 due to a missing capability check and insufficient validation. This makes it possible for unauthenticated attackers to update the plugins settings a...
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7
- Disclosed:
- Apr 20, 2020
WP Mega Menu [wp-megamenu] < 1.4.1
unknown
The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
WP Mega Menu [wp-megamenu] < 1.4.0
unknown
The plugin does not properly check for capability and CSRF due to a logic flaw, in its export_theme() and export_wp_megamenu_nav_menu () methods, hooked to admin_init. As a result, unauthenticated users can call them and access arbitrary post data, including password protected or private ones.
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.0
WP Mega Menu [wp-megamenu] < 1.4.1
unknown
The plugin does not properly check for capability and CSRF due to a logic flaw, in its export_theme() and export_wp_megamenu_nav_menu () methods, hooked as AJAX actions and available to any authenticated users. As a result, low privilege authenticated users such as subscribers can call them and access arbitrary post da...
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database