Showing 1 vulnerability on this page for WordPress Mega Menu plugin for WordPress

Signals CISA KEV Ransomware Nuclei
quadlayers vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress Mega Menu <= 2.0.6 - Arbitrary File Creation

The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, 2.0.6 via the compiler_save AJAX action. This makes it possible for unauthenticated attackers to create arbitrary PHP files that can be used to execute malicious code.

CWE-434Oct 16, 2024
CVSS9.8v3.1EPSS0.674%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX