CVE-2022-2276
22.08.2022, 15:15
The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow unauthenticated attackers to delete arbitrary posts/pages from the blog
Vendor | Product | Version |
---|---|---|
wp_edit_menu_project | wp_edit_menu | 𝑥 < 1.5.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References