The Advance Menu Manager plugin for WordPress is vulnerable to unauthorized changes to data. This means that someone with a subscriber-level account or higher can delete, create and duplicate menus without permission from the site owner. Versions of the plugin up to and including 3.0.6 are affected. However, version 3.0.7 added nonce checks which prevent the vulnerability from being used.