Cross-Site Request Forgery Vulnerability in Wow-Company Side Menu Lite
CVE-2025-24724
5.4MEDIUM
Key Information:
- Vendor
- Wow-company
- Status
- Side Menu Lite
- Vendor
- CVE Published:
- 24 January 2025
Summary
The Side Menu Lite plugin by Wow-Company contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to perform unauthorized actions on behalf of an authenticated user. This vulnerability affects all versions of the plugin leading up to 5.3.1, potentially compromising user accounts and application settings. It is crucial for users to be aware of this risk and apply necessary updates or mitigations.
Affected Version(s)
Side Menu Lite <= 5.3.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Khang Duong (Patchstack Alliance)