Impact
The Advance Nav Menu Manager plugin for WordPress contains an authorization bypass that allows any authenticated user with subscriber-level permissions or higher to duplicate, copy, move, or publish navigation menu items. The vulnerability arises because the plugin fails to verify whether the user is authorized to perform the anmm_save_menu_data action, which internally calls wp_insert_post() to create or modify nav_menu_item posts. This flaw permits attackers to alter the site’s navigation structure without proper approval, potentially enabling defacement or redirecting visitors to malicious destinations.
Affected Systems
Vendors: KrishaWeb. Product: Advance Nav Menu Manager plugin for WordPress, versions up to and including 1.3. No specific patch notes are provided for newer releases releases through v1.3.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity and the EPSS score is not available, suggesting low additional context. The vulnerability is not listed in the CISA KEV catalog. Attackers must already have authenticated access as a subscriber or higher, but once authenticated they can freely alter navigation menus, which could affect site usability and trust.
OpenCVE Enrichment