Description
WordPress Plugin WP Mega Menu is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently access arbitrary post data, including password protected or private posts. WordPress Plugin WP Mega Menu version 1.4.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.1 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:11E56EEF-77CD-41D7-B6B8-F75472CC0D1D
https://plugins.svn.wordpress.org/wp-megamenu/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Genesis Columns Advanced Cross-Site Scripting (2.0.3)
WordPress Plugin Best Image Gallery & Responsive Photo Gallery-FooGallery Security Bypass (1.6.15)
MySQL CVE-2019-2910 Vulnerability (CVE-2019-2910)
WordPress Plugin Sponsors Carousel Cross-Site Scripting (4.02)
Roundcube Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2009-4076)