WP Clinic
Entrar Registrarse

CVE · Medium

CVE-2024-2508 — WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.5

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-2508 WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.5 Falta de control de autorización Media 5,3 < 2.8.5 2.8.5 2024-07-30

CVE-2024-2508

The WP Mobile Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_menu_item_icon function in all versions up to, and including, 2.8.4.4. This makes it possible for unauthenticated attackers to add the '_mobmenu_icon' post meta to arbitrary posts with an arbitrary (but sanitized) value. NOTE: Version 2.8.4.4 contains a partial fix for this vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Escanea tu sitio WordPress gratis

Sin registro, sin tarjeta de crédito — ingresa tu URL y obtén un informe de seguridad en segundos.