Wp Edit Menu Project maintains a WordPress plugin focused on menu editing functionality, presenting a narrow but targeted exposure surface within the WordPress ecosystem. The observed vulnerability signal centers on authorization and request-validation issues such as cross-site request forgery and missing authorization controls, which are characteristic weaknesses in administrative WordPress plugins. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Edit Menu Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2276MEDIUM The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow unauthenticated attackers to delete arbitrary posts/pages f | Aug 22, 2022 | 4.3 | 14 | NO | NO |
CVE-2022-2275MEDIUM The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make a logged in admin delete arbitrary posts/pages from the blo | Aug 22, 2022 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Edit Menu Project.
Media articles that mention a CVE ID that affects a product developed by Wp Edit Menu Project — matched by CVE ID, not by vendor name.