CVE-2024-12774: Altra Side Menu <= 2.0 - Abitrary Menu Deletion via CSRF
The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary menu via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12774?
The severity of CVE-2024-12774 has not been officially rated, but it poses a significant risk due to the potential for CSRF attacks against admin users.
How do I fix CVE-2024-12774?
To fix CVE-2024-12774, update the Altra Side Menu plugin to the latest version or remove the plugin if an update is not available.
Which versions of the Altra Side Menu are affected by CVE-2024-12774?
CVE-2024-12774 affects all versions of the Altra Side Menu plugin up to and including version 2.0.
Can CVE-2024-12774 be exploited remotely?
Yes, CVE-2024-12774 can be exploited remotely if an attacker can trick a logged-in admin into performing an action via a malicious request.
What type of attack is associated with CVE-2024-12774?
CVE-2024-12774 is associated with cross-site request forgery (CSRF) attacks that can lead to arbitrary menu deletions by attackers.