CVE-2022-0450
The Menu Image, Icons made easy plugin prior to version 3.0.6 failed to implement authorization checks and cross-site request forgery protections on menu settings operations, while also lacking proper input validation and output escaping. This allowed any logged-in user, including those with subscriber-level permissions, to modify menu settings for arbitrary menus and inject malicious scripts that would execute when the affected menus displayed on the website frontend.
Based on public CVE data (MITRE/NVD).