First published: Mon Feb 21 2022(Updated: )
The Float menu WordPress plugin before 4.3.1 does not have CSRF check in place when deleting menu, which could allow attackers to make a logged in admin delete them via a CSRF attack
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wow-company Float Menu | <4.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0313 has a moderate severity due to the potential for an attacker to exploit the CSRF vulnerability to delete menu entries.
To fix CVE-2022-0313, update the Float menu WordPress plugin to version 4.3.1 or higher.
CVE-2022-0313 affects vulnerable versions of the Float menu WordPress plugin prior to 4.3.1.
Yes, exploitation of CVE-2022-0313 requires the attacker to have an authenticated session with admin privileges.
CVE-2022-0313 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to unauthorized actions on behalf of a logged-in user.