CVE-2022-2275
22.08.2022, 15:15
The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make a logged in admin delete arbitrary posts/pages from the blog via a CSRF attack
Vendor | Product | Version |
---|---|---|
wp_edit_menu_project | wp_edit_menu | 𝑥 < 1.5.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration