PT-2024-26786 · WordPress · Ubermenu

Mohamed Awad

+1

·

Published

2024-06-21

·

Updated

2024-08-20

·

CVE-2024-3593

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions UberMenu plugin for WordPress versions up to, and including, 3.8.3
Description The issue is due to missing or incorrect nonce validation on the ubermenu delete all item settings and ubermenu reset settings functions. This allows unauthenticated attackers to delete and reset the plugin's settings via a forged request if they can trick a site administrator into performing an action such as clicking on a link.
Recommendations For UberMenu plugin for WordPress versions up to, and including, 3.8.3, update to a version later than 3.8.3 to resolve the issue. As a temporary workaround, consider disabling the ubermenu delete all item settings and ubermenu reset settings functions until a patch is available.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-3593

Affected Products

Ubermenu