CVE-2021-24162: Responsive Menu < 4.0.4 - CSRF to Settings Update
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2021-24162.
What is the severity of CVE-2021-24162?
The severity of CVE-2021-24162 is high with a severity value of 8.8.
Which WordPress plugins are affected by CVE-2021-24162?
The Reponsive Menu (free and Pro) WordPress plugins before version 4.0.4 are affected by CVE-2021-24162.
How can an attacker exploit CVE-2021-24162?
To exploit CVE-2021-24162, an attacker can craft a request and trick an administrator into importing malicious JavaScript through modified settings.
Are there any references or additional information about CVE-2021-24162?
Yes, you can find more information about CVE-2021-24162 in the following references: [Reference 1](https://wpscan.com/vulnerability/923fc3a3-4bcc-4b48-870a-6150e14509b5), [Reference 2](https://www.wordfence.com/blog/2021/02/multiple-vulnerabilities-patched-in-responsive-menu-plugin/).