Description
WordPress Plugin WP Mega Menu is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently access arbitrary post data, including password protected or private posts. WordPress Plugin WP Mega Menu version 1.3.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.0 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:E40D8099-31AC-448E-9AD4-2D931A114A30
https://plugins.svn.wordpress.org/wp-megamenu/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin RSVPMaker Server-Side Request Forgery (8.7.2)
WordPress Plugin Timetable and Event Schedule by MotoPress Information Disclosure (2.3.19)
Apache 2.x version older than 2.2.6
WordPress Plugin Husker Portfolio Cross-Site Request Forgery (0.3)
WordPress Plugin WPFront User Role Editor Multiple Cross-Site Scripting Vulnerabilities (2.13)