CVE-2022-25602

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
18/03/2022
Last modified:
25/03/2022

Description

Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:expresstech:responsive_menu:*:*:*:*:*:wordpress:*:* 4.1.7 (including)