Freshlightlab's vulnerability footprint centers on WordPress plugins including Menu Image Icons Made Easy and WP Mobile Menu, with the observed exposure rooted in web application output-handling issues such as cross-site scripting and improper output encoding. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freshlightlab over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0450MEDIUM The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving menu settings, and does not validate, sanitise and escape them | Mar 28, 2022 | 5.4 | 20 | NO | NO |
CVE-2024-3987MEDIUM The WP Mobile Menu – The Mobile-Friendly Responsive Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, | Jun 7, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-50826MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Freshlight Lab Menu Image, Icons made easy allows Stored XSS.This issue affect | Dec 21, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freshlightlab.
Media articles that mention a CVE ID that affects a product developed by Freshlightlab — matched by CVE ID, not by vendor name.