Impact
ThemeHunk themehunk-megamenu-plus contains a missing authorization flaw (CWE‑862) that allows users with insufficient privileges to exploit incorrectly configured access controls. This weakness could let an attacker modify or view menu settings that should be restricted, potentially enabling unauthorized content changes or information disclosure within the WordPress site.
Affected Systems
The vulnerability affects the ThemeHunk themehunk‑megamenu‑plus plugin for WordPress in all releases up to and including version 1.2.0, as documented by the CNA.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to medium severity, and the EPSS score of less than 1 % shows a very low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog, suggesting it is not currently a focus of widespread attacks. Exploitation would likely occur through the normal administrative interfaces of a WordPress site where the plugin is installed, and would require the attacker to be authenticated but not necessarily an administrator.
OpenCVE Enrichment
EUVD