What the vulnerability does
01Description
Missing Authorization vulnerability in Megamenu Max Mega Menu.This issue affects Max Mega Menu: from n/a through 3.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Megamenu Max Mega Menu.This issue affects Max Mega Menu: from n/a through 3.3.
Explanation of Vulnerability in Simple Terms
Max Mega Menu versions 3.3 and earlier lack proper authorization checks, allowing authenticated users with low privileges to read and modify data they should not access. An attacker with a basic user account can view or change sensitive information within the plugin's scope. Update to a version newer than 3.3 to resolve this issue.
What an attacker can do
Read and modify data belonging to other users or restricted areas of the plugin.
Potential impact on your site
Unauthorized users can access and alter plugin settings or data not intended for their role.
Conditions required to exploit
Attacker must have a low-privilege user account on the site (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities