VYPR

Conditional Menus

by WordPress

Source repositories

CVEs (2)

  • CVE-2023-2654MedJun 19, 2023
    risk 0.40cvss 6.1epss 0.00

    The Conditional Menus WordPress plugin before 1.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2026-1032MedMar 26, 2026
    risk 0.21cvss 4.3epss 0.00

    The Conditional Menus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.6. This is due to missing nonce validation on the 'save_options' function. This makes it possible for unauthenticated attackers to modify conditional…