CVE-2021-24942
Summary
| CVE | CVE-2021-24942 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-26 13:15:00 UTC |
| Updated | 2023-11-07 03:31:00 UTC |
| Description | The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" option for WordPress menu items, which could allow highly privileged users to execute arbitrary PHP code even in a hardened environment. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Menu Item Visibility Control Project | Menu Item Visibility Control | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Menu Item Visibility Control <= 0.5 - Admin+ Arbitrary PHP Code Execution WordPress Security Vulnerability | MISC | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.