CVE-2024-8434: Easy Mega Menu Plugin for WordPress – ThemeHunk <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+) Settings Updates
The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform actions like updating plugin settings.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8434?
CVE-2024-8434 is considered a medium severity vulnerability due to unauthorized access risks for authenticated attackers.
How do I fix CVE-2024-8434?
To fix CVE-2024-8434, update the Easy Mega Menu Plugin for WordPress to version 1.1.0 or higher.
What is affected by CVE-2024-8434?
CVE-2024-8434 affects all versions of the Easy Mega Menu Plugin for WordPress up to and including 1.0.9.
Who can exploit CVE-2024-8434?
CVE-2024-8434 can be exploited by authenticated attackers who can access functions hooked via AJAX without proper capability checks.
What type of vulnerability is CVE-2024-8434?
CVE-2024-8434 is an unauthorized access vulnerability due to missing capability checks in the Easy Mega Menu Plugin.