The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.
Metrics
Affected Vendors & Products
References
History
Thu, 08 May 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wow-company
Wow-company float Menu |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:wow-company:float_menu:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wow-company
Wow-company float Menu |

Status: PUBLISHED
Assigner: WPScan
Published: 2024-05-02T06:00:02.127Z
Updated: 2024-08-01T19:11:53.477Z
Reserved: 2024-03-12T14:31:48.969Z
Link: CVE-2024-2405

Updated: 2024-08-01T19:11:53.477Z

Status : Analyzed
Published: 2024-05-02T06:15:49.947
Modified: 2025-05-08T18:43:32.867
Link: CVE-2024-2405

No data.