AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-0450

MEDIUM · CVSS 5.4 EPSS 0.60%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-03-28 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-0450
Severity
MEDIUM
CVSS
5.4
EPSS
0.60%
WordPress

Original NVD Description

The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving menu settings, and does not validate, sanitise and escape them. As a result, any authenticate users, such as subscriber can update the settings or arbitrary menu and put Cross-Site Scripting payloads in them which will be triggered in the related menu in the frontend