Security Advisory

CVE-2021-25113

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-04-04 15:35:39
Last updated 2024-08-03 19:56:10
Assigner WPScan
State PUBLISHED

Description

The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its settings, allowing low privilege users such as subscriber to update them. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues