CVE-2024-7894

Publication date

2024-12-07 01:45:53

Family

Wordfence

State

PUBLISHED

Description

The If Menu plugin for WordPress is vulnerable to unauthorized modification of the plugins license key due to a missing capability check on the actions function in versions up to, and including, 0.19.1. This makes it possible for unauthenticated attackers to modify delete or modify the license key.