Description
The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dsp_export_import_menus() function in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to export menu data and settings.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33570 | The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dsp_export_import_menus() function in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to export menu data and settings. |
References
History
Tue, 07 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Jan 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dsp_export_import_menus() function in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to export menu data and settings. | |
| Title | Export Import Menus <= 1.9.1 - Missing Authorization to Unauthenticated Menu Export | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:34:19.134Z
Reserved: 2024-11-05T14:22:28.306Z
Link: CVE-2024-10866
Updated: 2025-01-07T15:58:57.369Z
Status : Deferred
Published: 2025-01-07T08:15:23.060
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-10866
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD