The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dsp_export_import_menus() function in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to export menu data and settings.
References
Configurations
No configuration.
History
07 Jan 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-07 08:15
Updated : 2025-01-07 08:15
NVD link : CVE-2024-10866
Mitre link : CVE-2024-10866
CVE.ORG link : CVE-2024-10866
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization