Responsive Menu
by Expresstech
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-24160 | Hig | 0.58 | 8.8 | 0.08 | Apr 5, 2021 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code… | ||
| CVE-2021-24162 | Hig | 0.57 | 8.8 | 0.01 | Apr 5, 2021 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads… | ||
| CVE-2021-24161 | Hig | 0.57 | 8.8 | 0.01 | Apr 5, 2021 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further… | ||
| CVE-2017-18513 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface. | ||
| CVE-2022-25602 | Hig | 0.54 | 8.3 | 0.01 | Mar 18, 2022 | Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7). |
- risk 0.58cvss 8.8epss 0.08
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code…
- risk 0.57cvss 8.8epss 0.01
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads…
- risk 0.57cvss 8.8epss 0.01
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further…
- risk 0.57cvss 8.8epss 0.01
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
- risk 0.54cvss 8.3epss 0.01
Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).