Responsive Plus - Unauthenticated Arbitrary Shortcode Execution vulnerability
mediumUnauthenticated Arbitrary Shortcode Execution vulnerability
- CVSS:
- 6.5
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Mar 30, 2026
plugin
19 known security issues reported for the Responsive Add Ons WordPress plugin. Most recent disclosed Mar 30, 2026.
Running Responsive Add Ons on your site? Check whether your installed version is affected.
Scan your site freeUnauthenticated Arbitrary Shortcode Execution vulnerability
The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 3.4.3 (exclusive). This makes it possible for unauthenticated attackers to execute code on the server.
[en] The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software allowing unauthenticated users to execute the update_responsive_woo_free_shipping_left_shortcode AJAX action that does not properly validate the content_rech_data parameter before processing it as...
[en] Cross-Site Request Forgery (CSRF) vulnerability in CyberChimps Responsive Plus allows Cross Site Request Forgery. This issue affects Responsive Plus: from n/a through 3.2.2.
The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenti...
[en] Missing Authorization vulnerability in CyberChimps Responsive Plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Plus: from n/a through 3.2.0.
The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_sites() function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attack...
The Gutenberg & Elementor Templates Importer For Responsive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_items function in versions up to, and including, 3.1.9. This makes it possible for unauthenticated attackers to create items through the REST endpoint.
[en] Missing Authorization vulnerability in CyberChimps Gutenberg & Elementor Templates Importer For Responsive allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Gutenberg & Elementor Templates Importer For Responsive: from n/a through 3.1.9.
[en] The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.4 via the 'remote_request' function. This makes it possible for authenticated attackers, with contribut...
The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.4 via the 'remote_request' function. This makes it possible for authenticated attackers, with contributor-le...
[en] The Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This ma...
The Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes i...
The Responsive Starter Templates – Elementor & WordPress Templates is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.8. This allows authenticated users with administrator-level permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected pa...
The Responsive Starter Templates – Elementor & WordPress Templates plugin for WordPress is vulnerable to stored cross-site scripting in versions up to, and including, 2.6.8. This allows authenticated users with Administrator-level permissions or above to inject arbitrary web scripts in pages that will execute whenever...
The Responsive Starter Templates – Elementor & WordPress Templates is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.8. This allows authenticated users with administrator-level permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected pa...
The Responsive Starter Templates – Elementor & WordPress Templates plugin for WordPress is vulnerable to stored cross-site scripting in versions up to, and including, 2.6.8. This allows authenticated users with Administrator-level permissions or above to inject arbitrary web scripts in pages that will execute whenever...
[en] The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests.
The Responsive Ready Sites Importer for WordPress is vulnerable to authorization bypass due missing capability checks on several AJAX actions in versions up to, and including, 2.2.6. This makes it possible for authenticated attackers with minimal permissions, such as subscribers, to perform a variety of unauthorized ac...
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free