CVE-2024-54282: WordPress WP Mega Menu plugin <= 1.4.2 - PHP Object Injection vulnerability
Published Dec 13, 2024
·Updated
Deserialization of Untrusted Data vulnerability in Themeum WP Mega Menu wp-megamenu allows Object Injection.This issue affects WP Mega Menu: from n/a through <= 1.4.2.
Affected Software
1 affected component
Themeum WP Mega Menu<=1.4.2
Event History
Dec 13, 2024
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-54282?
CVE-2024-54282 is categorized as a critical vulnerability due to the potential for object injection and unauthorized access.
2
How do I fix CVE-2024-54282?
To fix CVE-2024-54282, you should update the Themeum WP Mega Menu plugin to version 1.4.3 or higher.
3
What versions of WP Mega Menu are affected by CVE-2024-54282?
CVE-2024-54282 affects all versions of WP Mega Menu from n/a up to and including 1.4.2.
4
What type of vulnerability is CVE-2024-54282?
CVE-2024-54282 is a deserialization of untrusted data vulnerability which enables object injection.
5
Who is the vendor for the WP Mega Menu affected by CVE-2024-54282?
The vendor for the affected WP Mega Menu is Themeum.