Export Import Menus WordPress Plugin Missing Authorization Vulnerability

Vulnerability

A vulnerability exists in the Export Import Menus plugin for WordPress, in all versions through 1.9.1. The issue arises from a lack of proper capability checks in the 'dsp_export_import_menus()' function, allowing unauthenticated users to export menu data and settings without authorization.

Impact

Exploitation of this vulnerability allows for unauthorized access to menu data and settings, enabling attackers to export this information without proper authorization.

Remediation

Users are advised to update the Export Import Menus WordPress plugin to version 1.9.2 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.1
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.