CVE-2022-0450

T

he Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving menu settings, and does not validate, sanitise and escape them. As a result, any authenticate users, such as subscriber can update the settings or arbitrary menu and put Cross-Site Scripting payloads in them which will be triggered in the related menu in the frontend

Configurations

Configuration 1 (hide)

cpe:2.3:a:freshlightlab:menu_image\,_icons_made_easy:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 06:38

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/612f9273-acc8-4be6-b372-33f1e687f54a - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/612f9273-acc8-4be6-b372-33f1e687f54a - Exploit, Third Party Advisory

Information

Published : 2022-03-28 18:15

Updated : 2024-11-21 06:38


NVD link : CVE-2022-0450

Mitre link : CVE-2022-0450

CVE.ORG link : CVE-2022-0450


JSON object : View

CWE
CWE-116

Improper Encoding or Escaping of Output