CVE-2022-0450

MEDIUM

Menu Image Icons made easy <3.0.6 - CSRF

Title source: llm
STIX 2.1

Description

The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving menu settings, and does not validate, sanitise and escape them. As a result, any authenticate users, such as subscriber can update the settings or arbitrary menu and put Cross-Site Scripting payloads in them which will be triggered in the related menu in the frontend

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/612f9273-acc8-4be6-b372-33f1e687f54a

Scores

CVSS v3 5.4
EPSS 0.0060
EPSS Percentile 43.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-116
Status published
Products (1)
freshlightlab/menu_image\,_icons_made_easy < 3.0.8
Published Mar 28, 2022
Tracked Since Feb 18, 2026