The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.
History

Thu, 08 May 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Wow-company
Wow-company float Menu
Weaknesses CWE-352
CPEs cpe:2.3:a:wow-company:float_menu:*:*:*:*:*:wordpress:*:*
Vendors & Products Wow-company
Wow-company float Menu

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-05-02T06:00:02.127Z

Updated: 2024-08-01T19:11:53.477Z

Reserved: 2024-03-12T14:31:48.969Z

Link: CVE-2024-2405

cve-icon Vulnrichment

Updated: 2024-08-01T19:11:53.477Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-02T06:15:49.947

Modified: 2025-05-08T18:43:32.867

Link: CVE-2024-2405

cve-icon Redhat

No data.