CVE · Medium

CVE-2022-0450 — Menu Image, Icons made easy [menu-image] < 3.0.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0450 Menu Image, Icons made easy [menu-image] < 3.0.8 Improper Encoding or Escaping of Output Medium 5.4 < 3.0.8 3.0.8 2022-03-07

CVE-2022-0450

The Menu Image, Icons made easy plugin prior to version 3.0.6 failed to implement authorization checks and cross-site request forgery protections on menu settings operations, while also lacking proper input validation and output escaping. This allowed any logged-in user, including those with subscriber-level permissions, to modify menu settings for arbitrary menus and inject malicious scripts that would execute when the affected menus displayed on the website frontend.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.