UberMenu Plugin Vulnerable to Cross-Site Request Forgery
CVE-2024-3593
What is CVE-2024-3593?
The UberMenu plugin for WordPress exhibits a security flaw that allows unauthenticated attackers to exploit weaknesses in nonce validation. In versions up to and including 3.8.3, the functions responsible for deleting and resetting settings are susceptible to Cross-Site Request Forgery (CSRF). If an attacker successfully tricks an administrator into clicking a malicious link, they can initiate unauthorized actions, such as deleting the plugin's settings. This vulnerability poses significant risks to site configuration and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
UberMenu * <= 3.8.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved