CVE-2024-2405

Severity
4.5MEDIUM
EPSS
0.2%
top 59.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2

Description

The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:NExploitability: 0.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5unknown/float_menu< 6.0.1

🔴Vulnerability Details

2
CVEList
Float menu < 6.0.1 - Menu Deletion via CSRF2024-05-02
GHSA
GHSA-mgmj-jff7-4w5p: The Float menu WordPress plugin before 62024-05-02
CVE-2024-2405 (MEDIUM CVSS 4.5) | The Float menu WordPress plugin bef | cvebase.io