Vulnerabilities > Dropdown Menu Widget Project

DATE CVE VULNERABILITY TITLE RISK
2022-04-04 CVE-2021-25113 Cross-site Scripting vulnerability in Dropdown Menu Widget Project Dropdown Menu Widget
The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its settings, allowing low privilege users such as subscriber to update them.
3.5