Description
Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor admin-menu-editor allows Cross Site Request Forgery.This issue affects Admin Menu Editor: from n/a through <= 1.14.1.
Published: 2026-03-13
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site Request Forgery (CSRF)
Action: Patch
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery (CSRF) flaw in the Janis Elsts Admin Menu Editor plugin for WordPress, identified as CWE‑352. The issue allows an attacker to force an authenticated WordPress user to perform actions within the plugin without the user’s awareness. While the vendor description does not specify the exact actions that could be performed, it is inferred that typical outcomes of a CSRF in this context may include altering menu configurations or changing plugin settings. This inference is based on the nature of CSRF attacks and the fact that the plugin provides administrative capabilities.

Affected Systems

All installations of the Admin Menu Editor plugin up to and including version 1.14.1 are vulnerable. The vulnerability is independent of the WordPress core version; it affects any site that has the plugin installed and accessible. The CVE data indicates the affected range is "from n/a through <= 1.14.1." Versions 1.14.2 and later are presumed to address the issue, but site owners should verify the vendor release notes.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. The EPSS score is below 1 %, suggesting a low probability of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that a malicious site can trigger an unauthorized request while the victim is logged into WordPress with sufficient privileges. No additional preconditions beyond user authentication are specified in the vendor data. The risk assessment therefore relies on the CVSS score and the low EPSS probability, indicating that exploitation is unlikely but still possible if the conditions align.

Generated by OpenCVE AI on March 19, 2026 at 17:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Admin Menu Editor plugin to any version above 1.14.1, preferably 1.14.2 or later.
  • If upgrading is not feasible, consider disabling or uninstalling the plugin to eliminate the vulnerability.
  • Restrict access to privileged users and monitor for suspicious activity if the plugin remains installed.

Generated by OpenCVE AI on March 19, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Janis Elsts
Janis Elsts admin Menu Editor
Wordpress
Wordpress wordpress
Vendors & Products Janis Elsts
Janis Elsts admin Menu Editor
Wordpress
Wordpress wordpress

Fri, 13 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor admin-menu-editor allows Cross Site Request Forgery.This issue affects Admin Menu Editor: from n/a through <= 1.14.1.
Title WordPress Admin Menu Editor plugin <= 1.14.1 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Janis Elsts Admin Menu Editor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:16:21.188Z

Reserved: 2026-03-12T11:11:40.510Z

Link: CVE-2026-32456

cve-icon Vulnrichment

Updated: 2026-03-13T14:20:05.782Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-13T19:55:07.590

Modified: 2026-03-16T14:53:46.157

Link: CVE-2026-32456

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-23T12:03:09Z

Weaknesses