Lucene search

K
wpvulndbErwan LR (WPScan)WPVDB-ID:C42FFA15-6EBE-4C70-9E51-B95BD05EA04D
HistoryApr 11, 2024 - 12:00 a.m.

Float menu < 6.0.1 - Menu Deletion via CSRF

2024-04-1100:00:00
Erwan LR (WPScan)
wpscan.com
9
float menu plugin
csrf attack
menu deletion
security vulnerability

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%

Description The plugin does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.

PoC

Make a logged in admin open one a page with the code below, this will make them delete the menu with ID 1:

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%

Related for WPVDB-ID:C42FFA15-6EBE-4C70-9E51-B95BD05EA04D