PT-2024-24541 · WordPress · Superfly Responsive Menu

Mohamed Awad

·

Published

2024-08-02

·

Updated

2024-08-02

·

CVE-2024-3238

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress versions up to and including 5.0.29
Description The issue is related to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the ajax handle delete icons() function. This allows unauthenticated attackers to delete arbitrary files by tricking a site administrator into performing an action, such as clicking on a link.
Recommendations For versions up to and including 5.0.29, update to version 5.0.30 or later to resolve the issue. As a temporary workaround, consider restricting access to the ajax handle delete icons() function until a patch is applied.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-3238

Affected Products

Superfly Responsive Menu