plugin

Responsive Add Ons Vulnerabilities

19 known security issues reported for the Responsive Add Ons WordPress plugin. Most recent disclosed Mar 30, 2026.

2 critical 8 medium

Running Responsive Add Ons on your site? Check whether your installed version is affected.

Scan your site free

Responsive Plus - Unauthenticated Arbitrary Shortcode Execution vulnerability

medium

Unauthenticated Arbitrary Shortcode Execution vulnerability

CVSS:
6.5
Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Mar 30, 2026

Responsive Plus – Elementor Templates & Starter Sites < 3.4.3 - Unauthenticated Arbitrary Code Execution

critical

The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 3.4.3 (exclusive). This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Mar 30, 2026

CVE-2025-15488 on NVD →

Responsive Plus – Elementor Templates &amp; Starter Sites [responsive-add-ons] < 3.4.3

unknown

[en] The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software allowing unauthenticated users to execute the update_responsive_woo_free_shipping_left_shortcode AJAX action that does not properly validate the content_rech_data parameter before processing it as...

Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Mar 26, 2026

CVE-2025-15488 on NVD →

Responsive Plus – Elementor Templates &amp; Starter Sites [responsive-add-ons] < 3.2.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in CyberChimps Responsive Plus allows Cross Site Request Forgery. This issue affects Responsive Plus: from n/a through 3.2.2.

Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Jun 17, 2025

CVE-2025-49856 on NVD →

Responsive Plus <= 3.2.2 - Cross-Site Request Forgery to Settings Update

medium

The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenti...

CVSS:
4.3
Affected:
up to 3.2.2
Fixed in:
3.2.3
Disclosed:
Jun 12, 2025

CVE-2025-49856 on NVD →

Responsive Plus – Elementor Templates &amp; Starter Sites [responsive-add-ons] < 3.2.1

unknown

[en] Missing Authorization vulnerability in CyberChimps Responsive Plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Plus: from n/a through 3.2.0.

Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Jun 6, 2025

CVE-2025-48335 on NVD →

Responsive Plus <= 3.2.0 - Missing Authorization

medium

The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_sites() function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attack...

CVSS:
4.3
Affected:
up to 3.2.0
Fixed in:
3.2.1
Disclosed:
May 29, 2025

CVE-2025-48335 on NVD →

Gutenberg & Elementor Templates Importer For Responsive <= 3.1.9 - Missing Authorization

medium

The Gutenberg & Elementor Templates Importer For Responsive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_items function in versions up to, and including, 3.1.9. This makes it possible for unauthenticated attackers to create items through the REST endpoint.

CVSS:
5.3
Affected:
up to 3.1.9
Fixed in:
3.2.0
Disclosed:
May 7, 2025

CVE-2025-47486 on NVD →

Responsive Plus – Elementor Templates &amp; Starter Sites [responsive-add-ons] < 3.2.0

unknown

[en] Missing Authorization vulnerability in CyberChimps Gutenberg & Elementor Templates Importer For Responsive allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Gutenberg & Elementor Templates Importer For Responsive: from n/a through 3.1.9.

Affected:
up to 3.2.0
Fixed in:
3.2.0
Disclosed:
May 7, 2025

CVE-2025-47486 on NVD →

Responsive Plus – Elementor Templates &amp; Starter Sites [responsive-add-ons] < 3.1.5

unknown

[en] The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.4 via the 'remote_request' function. This makes it possible for authenticated attackers, with contribut...

Affected:
up to 3.1.5
Fixed in:
3.1.5
Disclosed:
Feb 15, 2025

CVE-2024-13834 on NVD →

Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme <= 3.1.4 - Authenticated (Contributor+) Blind Server-Side Request Forgery via remote_request

medium

The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.4 via the 'remote_request' function. This makes it possible for authenticated attackers, with contributor-le...

CVSS:
5.4
Affected:
up to 3.1.4
Fixed in:
3.1.5
Disclosed:
Feb 14, 2025

CVE-2024-13834 on NVD →

Responsive Plus – Elementor Templates &amp; Starter Sites [responsive-add-ons] < 3.0.6

unknown

[en] The Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This ma...

Affected:
up to 3.0.6
Fixed in:
3.0.6
Disclosed:
Jun 5, 2024

CVE-2024-5222 on NVD →

Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. <= 3.0.5 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes i...

CVSS:
6.4
Affected:
up to 3.0.5
Fixed in:
3.0.6
Disclosed:
Jun 4, 2024

CVE-2024-5222 on NVD →

Responsive Starter Templates – Elementor & WordPress Templates <= 2.6.8 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Responsive Starter Templates – Elementor & WordPress Templates is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.8. This allows authenticated users with administrator-level permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected pa...

CVSS:
5.5
Affected:
up to 2.6.8
Fixed in:
2.6.9
Disclosed:
Dec 13, 2022

Responsive Starter Templates – Elementor & WordPress Templates <= 2.6.8 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Responsive Starter Templates – Elementor & WordPress Templates plugin for WordPress is vulnerable to stored cross-site scripting in versions up to, and including, 2.6.8. This allows authenticated users with Administrator-level permissions or above to inject arbitrary web scripts in pages that will execute whenever...

CVSS:
5.5
Affected:
up to 2.6.8
Fixed in:
2.6.9
Disclosed:
Dec 13, 2022

Responsive Plus – Elementor Templates &amp; Starter Sites [responsive-add-ons] < 2.6.9

unknown

The Responsive Starter Templates – Elementor & WordPress Templates is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.8. This allows authenticated users with administrator-level permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected pa...

Affected:
up to 2.6.9
Fixed in:
2.6.9
Disclosed:
Dec 13, 2022

Responsive Plus – Elementor Templates &amp; Starter Sites [responsive-add-ons] < 2.6.9

unknown

The Responsive Starter Templates – Elementor & WordPress Templates plugin for WordPress is vulnerable to stored cross-site scripting in versions up to, and including, 2.6.8. This allows authenticated users with Administrator-level permissions or above to inject arbitrary web scripts in pages that will execute whenever...

Affected:
up to 2.6.9
Fixed in:
2.6.9
Disclosed:
Dec 13, 2022

Responsive Plus – Elementor Templates &amp; Starter Sites [responsive-add-ons] < 2.2.7

unknown

[en] The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests.

Affected:
up to 2.2.7
Fixed in:
2.2.7
Disclosed:
Apr 23, 2020

CVE-2020-12073 on NVD →

Responsive Ready Sites Importer <= 2.2.6 - Unprotected AJAX Actions

critical

The Responsive Ready Sites Importer for WordPress is vulnerable to authorization bypass due missing capability checks on several AJAX actions in versions up to, and including, 2.2.6. This makes it possible for authenticated attackers with minimal permissions, such as subscribers, to perform a variety of unauthorized ac...

CVSS:
9.1
Affected:
up to 2.2.6
Fixed in:
2.2.7
Disclosed:
Mar 4, 2020

CVE-2020-12073 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database