VYPR
Medium severity5.4NVD Advisory· Published Jan 24, 2025· Updated Apr 23, 2026

CVE-2025-24724

CVE-2025-24724

Description

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite side-menu-lite allows Cross Site Request Forgery.This issue affects Side Menu Lite: from n/a through <= 5.3.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A CSRF vulnerability in Side Menu Lite <=5.3.1 allows an attacker to trick a privileged user into changing plugin settings without consent.

This Cross-Site Request Forgery (CSRF) vulnerability affects the Side Menu Lite WordPress plugin (side-menu-lite) from Wow-Company, up to version 5.3.1. The root cause is a missing or insufficient nonce validation on settings-change endpoints, which allows an attacker to forge requests on behalf of an authenticated administrator.

To exploit this flaw, an attacker must convince a logged-in user with administrative privileges to click a crafted link, visit a malicious page, or submit a form. No additional authentication is required beyond the victim's session. The attack does not require direct network access to the target server — it can be delivered via email, social engineering, or other web-based vectors.

Successful exploitation could force the victim's browser to perform unauthorized actions, such as modifying plugin settings (e.g., changing menu appearance or behavior). While the CVSS v3 score is 5.4 (Medium), the vendor and Patchstack note that the overall impact is low and mass exploitation is unlikely without social engineering.

The vulnerability is patched in version 5.3.2. Users are strongly advised to update immediately. For sites that cannot update, enabling auto-updates for vulnerable plugins (e.g., via Patchstack) is recommended. As noted in reference [1], this is not currently listed on CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.