{"api_version":"1","generated_at":"2026-07-23T15:00:23+00:00","cve":"CVE-2021-24942","urls":{"html":"https://cve.report/CVE-2021-24942","api":"https://cve.report/api/cve/CVE-2021-24942.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-24942","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-24942"},"summary":{"title":"CVE-2021-24942","description":"The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the \"Visibility logic\" option for WordPress menu items, which could allow highly privileged users to execute arbitrary PHP code even in a hardened environment.","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2022-12-26 13:15:00","updated_at":"2023-11-07 03:31:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/eaa28832-74c1-4cd5-9b0f-02338e23b418","name":"https://wpscan.com/vulnerability/eaa28832-74c1-4cd5-9b0f-02338e23b418","refsource":"MISC","tags":[],"title":"Menu Item Visibility Control <= 0.5 - Admin+ Arbitrary PHP Code Execution WordPress Security Vulnerability","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-24942","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-24942","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"24942","vulnerable":"1","versionEndIncluding":"0.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"menu_item_visibility_control_project","cpe5":"menu_item_visibility_control","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2021-24942","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the \"Visibility logic\" option for WordPress menu items, which could allow highly privileged users to execute arbitrary PHP code even in a hardened environment."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-94 Improper Control of Generation of Code ('Code Injection')"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Unknown","product":{"product_data":[{"product_name":"Menu Item Visibility Control","version":{"version_data":[{"version_value":"0","version_affected":"="}]}}]}}]}},"references":{"reference_data":[{"url":"https://wpscan.com/vulnerability/eaa28832-74c1-4cd5-9b0f-02338e23b418","refsource":"MISC","name":"https://wpscan.com/vulnerability/eaa28832-74c1-4cd5-9b0f-02338e23b418"}]},"generator":{"engine":"WPScan CVE Generator"},"source":{"discovery":"EXTERNAL"},"credits":[{"lang":"en","value":"bl4derunner"},{"lang":"en","value":"WPScan"}]},"nvd":{"publishedDate":"2022-12-26 13:15:00","lastModifiedDate":"2023-11-07 03:31:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:menu_item_visibility_control_project:menu_item_visibility_control:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"0.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"24942","Ordinal":"199704","Title":"CVE-2021-24942","CVE":"CVE-2021-24942","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"24942","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}