PT-2026-51684 · Krishaweb · Advance Nav Menu Manager

Hardik Patel

·

Publicado

2026-06-24

·

Atualizado

2026-06-24

·

CVE-2026-8688

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to duplicate, copy, move, or publish nav menu item posts via wp insert post(), modifying the site's navigation menus without authorization.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-8688

Produtos afetados

Advance Nav Menu Manager