CVE · Medium

CVE-2024-28003 — Max Mega Menu [megamenu] < 3.3.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-28003 Max Mega Menu [megamenu] < 3.3.1 Missing Authorization Medium 5.4 < 3.3.1 3.3.1 2024-03-26

CVE-2024-28003

The Max Mega Menu plugin for WordPress contains a broken access control flaw in versions prior to 3.3.1 that was discovered by Rafie Muhammad. The vulnerability stems from inadequate authorization and authentication checks, allowing users without proper privileges to perform actions restricted to higher-privileged accounts. Updating to version 3.3.1 or later resolves this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.