1 results (0.007 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

22 Feb 2021 — The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, 2.0.6 via the compiler_save AJAX action. This makes it possible for unauthenticated attackers to create arbitrary PHP files that can be used to execute malicious code. • https://www.wordfence.com/threat-intel/vulnerabilities/id/04003542-fd62-4587-9834-70e7fe8f08ef?source=cve • CWE-434: Unrestricted Upload of File with Dangerous Type •