7.2

CVE-2021-24942

Exploit

Menu Item Visibility Control <= 0.5 - Admin+ Arbitrary PHP Code Execution

Menu Item Visibility Control <= 0.5 - Authenticated (Admin+) Remote Code Execution

The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" option for WordPress menu items, which could allow highly privileged users to execute arbitrary PHP code even in a hardened environment.
Mögliche Gegenmaßnahme
Menu Item Visibility Control: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Menu Item Visibility Control
Version *-0.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.23% 0.649
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/eaa28832-74c1-4cd5-9b0f-02338e23b418
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/6e15a7b0-2b0e-468d-a245-cec2ed77d73b
Third Party Advisory