The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" option for WordPress menu items, which could allow highly privileged users to execute arbitrary PHP code even in a hardened environment.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/eaa28832-74c1-4cd5-9b0f-02338e23b418 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-12-26 05:15
Updated : 2023-01-05 06:25
NVD link : CVE-2021-24942
Mitre link : CVE-2021-24942
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
menu_item_visibility_control_project
- menu_item_visibility_control