PT-2024-11039 · WordPress · Wordpress Mega Menu

Mikel Gorraiz

+1

·

Published

2024-10-15

·

Updated

2024-10-21

·

CVE-2021-4443

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress Mega Menu plugin versions up to, and including, 2.0.6
Description The WordPress Mega Menu plugin is vulnerable to Arbitrary File Creation, allowing unauthenticated attackers to create arbitrary PHP files that can be used to execute malicious code via the compiler save AJAX action. This vulnerability enables remote code execution. Users are urged to update to the latest version immediately to mitigate risks.
Recommendations For WordPress Mega Menu plugin versions up to, and including, 2.0.6, update to the latest version immediately to resolve the issue. As a temporary workaround, consider disabling the compiler save AJAX action until a patch is available. Restrict access to the vulnerable plugin to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2021-4443

Affected Products

Wordpress Mega Menu