← Back

Dropdown Menu Widget

dropdown_menu_widget

Vendor: Dropdown Menu Widget Project • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dropdown Menu Widget Project
1Dropdown Menu Widget
Jun 17, 2026
Apr 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its settings, allowing low privilege users such as subscriber to update them. Due to the lack of sanitisatio...Show more
The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its settings, allowing low privilege users such as subscriber to update them. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issuesShow less