Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2024-2405
HistoryMay 02, 2024 - 6:00 a.m.

CVE-2024-2405 Float menu < 6.0.1 - Menu Deletion via CSRF

2024-05-0206:00:02
WPScan
github.com
3
cve-2024-2405; float menu; wordpress; csrf attack; menu deletion; admin; security vulnerability

AI Score

6.8

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:wow-company:float_menu:-:*:*:*:*:wordpress:*:*"
    ],
    "vendor": "wow-company",
    "product": "float_menu",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "6.0.1",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

6.8

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-2405