← Zuruck zu CVEs
CVE-2021-24162
HIGH8.8
Beschreibung
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.
CVE Details
CVSS v3.1 Bewertung8.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht4/5/2021
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
expresstech:responsive_menu
Schwachen (CWE)
CWE-352CWE-352
Referenzen
https://wpscan.com/vulnerability/923fc3a3-4bcc-4b48-870a-6150e14509b5(contact@wpscan.com)
https://www.wordfence.com/blog/2021/02/multiple-vulnerabilities-patched-in-responsive-menu-plugin/(contact@wpscan.com)
https://wpscan.com/vulnerability/923fc3a3-4bcc-4b48-870a-6150e14509b5(af854a3a-2127-422b-91ae-364da2661108)
https://www.wordfence.com/blog/2021/02/multiple-vulnerabilities-patched-in-responsive-menu-plugin/(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.