PT-2025-1729 · WordPress · Wp Menu Image

Published

2025-01-07

·

Updated

2025-01-17

·

CVE-2024-12022

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Menu Image plugin for WordPress versions up to, and including, 2.2
Description The issue is related to a missing capability check on the wmi delete img menu function, which allows unauthenticated attackers to delete images from menus. This makes it possible for unauthorized modification of data.
Recommendations For versions up to, and including, 2.2, consider disabling the wmi delete img menu function until a patch is available to prevent unauthorized deletion of images from menus. Update to a version that includes a fix for this issue, as the current version has a missing capability check that poses a security risk.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-12022

Affected Products

Wp Menu Image