Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Wp Edit Menu Project Subscribe
Filtered by product Wp Edit Menu
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-2276 1 Wp Edit Menu Project 1 Wp Edit Menu 2022-08-24 N/A 4.3 MEDIUM
The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow unauthenticated attackers to delete arbitrary posts/pages from the blog
CVE-2022-2275 1 Wp Edit Menu Project 1 Wp Edit Menu 2022-08-24 N/A 4.3 MEDIUM
The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make a logged in admin delete arbitrary posts/pages from the blog via a CSRF attack