CVE-2022-25602: WordPress Responsive Menu plugin <= 4.1.7 - Nonce token leak leading to arbitrary file upload, theme deletion, plugin settings change vulnerability
Published Mar 18, 2022
·Updated
Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).
Affected Software
1 affected component
ExpressTech Responsive Menu Wordpress<=4.1.7
Remediation
Information
Update to 4.1.8 or higher version.
Event History
Mar 18, 2022
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-25602?
CVE-2022-25602 is a nonce token leak vulnerability leading to arbitrary file upload, theme deletion, and plugin settings change discovered in the Responsive Menu WordPress plugin (versions <= 4.1.7).
2
What is the severity of CVE-2022-25602?
CVE-2022-25602 has a severity rating of 8.8 (high).
3
Which software is affected by CVE-2022-25602?
The Responsive Menu WordPress plugin (versions <= 4.1.7) is affected by CVE-2022-25602.
4
How can I fix CVE-2022-25602?
To fix CVE-2022-25602, update the Responsive Menu WordPress plugin to a version higher than 4.1.7.
5
Where can I find more information about CVE-2022-25602?
You can find more information about CVE-2022-25602 on the Patchstack database and the official WordPress plugin page for Responsive Menu.