CVE-2022-25602
WordPress Responsive Menu plugin <= 4.1.7 - Nonce token leak leading to arbitrary file upload, theme deletion, plugin settings change vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).
Se ha detectado una vulnerabilidad de filtrado de token nonce que conlleva a una carga arbitraria de archivos, la eliminación de temas y el cambio de la configuración del plugin en el plugin Responsive Menu de WordPress (versiones anteriores a 4.1.7 incluyéndola)
The Responsive Menu plugin for WordPress is vulnerable to authorization bypass due to missing authorization checks on various functions and nonce disclosure in versions up to, and including 4.1.7. This makes it possible for attackers to upload arbitrary files, delete themes, and change plugin settings.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-21 CVE Reserved
- 2022-03-16 CVE Published
- 2024-09-17 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-434: Unrestricted Upload of File with Dangerous Type
- CWE-862: Missing Authorization
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Expresstech Search vendor "Expresstech" | Responsive Menu Search vendor "Expresstech" for product "Responsive Menu" | <= 4.1.7 Search vendor "Expresstech" for product "Responsive Menu" and version " <= 4.1.7" | wordpress |
Affected
|