CVE-2022-0450 Information
Jun 07, 2022
cve
Description
The Menu Image Icons made easy WordPress plugin before 3.0.8 does not have authorisation and CSRF checks when saving menu settings and does not validate sanitise and escape them. As a result any authenticate users such as subscriber can update the settings or arbitrary menu and put Cross-Site Scripting payloads in them which will be triggered in the related menu in the frontend
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://wpscan.com/vulnerability/612f9273-acc8-4be6-b372-33f1e687f54a
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: