CVE-2022-0628: AP Mega Menu < 3.0.8 - Reflected Cross-Site Scripting
The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0628?
CVE-2022-0628 is a vulnerability in the Mega Menu WordPress plugin before version 3.0.8 that allows for Reflected Cross-Site Scripting.
What is the severity of CVE-2022-0628?
The severity of CVE-2022-0628 is medium with a CVSS score of 6.1.
How does CVE-2022-0628 affect the Mega Menu WordPress plugin?
CVE-2022-0628 affects the Mega Menu WordPress plugin before version 3.0.8 by allowing for Reflected Cross-Site Scripting.
How can I fix CVE-2022-0628?
To fix CVE-2022-0628, update the Mega Menu WordPress plugin to version 3.0.8 or later.
Where can I find more information about CVE-2022-0628?
You can find more information about CVE-2022-0628 at the following references: [Link 1](https://plugins.trac.wordpress.org/changeset/2684307) and [Link 2](https://wpscan.com/vulnerability/af9787ee-c496-4f02-a22c-c8f8a97ad902).