CVE-2024-7894
07.12.2024, 02:15
The If Menu plugin for WordPress is vulnerable to unauthorized modification of the plugin's license key due to a missing capability check on the 'actions' function in versions up to, and including, 0.19.1. This makes it possible for unauthenticated attackers to modify delete or modify the license key.Enginsight
Vendor | Product | Version |
---|---|---|
andreiigna | if_menu | 𝑥 ≤ 0.19.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References