WP Responsive Menu <= 3.1.7 - Missing Authorization to Settings Update & Stored Cross-Site Scripting

2022-01-26 00:00
Krzysztof Zając

Strategic Overview

Status
Patched in 3.1.7.1
Affected PluginWP Responsive Menu
Affected Version<= 3.1.7
CVSS5.4Medium
CVECVE-2021-24971
View all WP Responsive Menu vulnerabilities

Vulnerability Overview

The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of the data submitted. As a result, any authenticated, such as subscriber could update the plugin's settings and perform Cross-Site Scripting attacks against all visitor and users on the frontend

Technical Analysis

REMEDIATION: Update to version 3.1.7.1, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C

WP Responsive Menu <= 3.1.7 - Missing Authorization to Settings Update & Stored Cross-Site Scripting (CVE-2021-24971)