Responsive Tabs
by WordPress
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-4096 | Med | 0.38 | 5.9 | 0.00 | Jul 30, 2024 | The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks | ||
| CVE-2023-45635 | Med | 0.35 | 5.4 | 0.00 | Jun 4, 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs allows Code Injection.This issue affects Responsive Tabs: from n/a before 4.0.6. | ||
| CVE-2024-1846 | Med | 0.35 | 5.4 | 0.01 | Apr 15, 2024 | The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site… | ||
| CVE-2018-5312 | Med | 0.35 | 5.4 | 0.01 | Jan 9, 2018 | The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to wp-admin/post.php. | ||
| CVE-2021-36893 | Med | 0.31 | 4.8 | 0.01 | Apr 11, 2022 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5 | ||
| CVE-2026-65550 | Med | 0.00 | 5.9 | 0.00 | Jul 23, 2026 | Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. |
- risk 0.38cvss 5.9epss 0.00
The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks
- risk 0.35cvss 5.4epss 0.00
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs allows Code Injection.This issue affects Responsive Tabs: from n/a before 4.0.6.
- risk 0.35cvss 5.4epss 0.01
The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site…
- risk 0.35cvss 5.4epss 0.01
The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to wp-admin/post.php.
- risk 0.31cvss 4.8epss 0.01
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5
- risk 0.00cvss 5.9epss 0.00
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.