Altra Side Menu WordPress Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in the Altra Side Menu WordPress plugin, affecting versions through 2.0. The vulnerability arises because the plugin lacks adequate CSRF protections in certain areas, potentially allowing attackers to exploit logged-in administrators into deleting arbitrary menu items.

Impact

Exploitation of this vulnerability could lead to unauthorized deletion of menu items by exploiting the CSRF weakness, targeting logged-in admin users.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.