CVE · Medium

CVE-2024-2508 — WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2508 WP Mobile Menu – The Mobile-Friendly Responsive Menu [mobile-menu] < 2.8.5 Missing Authorization Medium 5.3 < 2.8.5 2.8.5 2024-07-30

CVE-2024-2508

The WP Mobile Menu plugin contains a flaw in the save_menu_item_icon function that fails to verify user permissions, affecting all versions through 2.8.4.4. This vulnerability allows unauthenticated attackers to add the '_mobmenu_icon' post meta to any post with a sanitized but attacker-controlled value. The plugin maintainers released version 2.8.4.4 as a partial mitigation, and the issue is fully resolved in version 2.8.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.