plugin

Responsive Menu Vulnerabilities

14 known security issues reported for the Responsive Menu WordPress plugin. Most recent disclosed Mar 18, 2022.

4 high 1 medium

Running Responsive Menu on your site? Check whether your installed version is affected.

Scan your site free

Responsive Menu &#8211; Create Mobile-Friendly Menu [responsive-menu] < 4.1.8

unknown

[en] Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).

Affected:
up to 4.1.8
Fixed in:
4.1.8
Disclosed:
Mar 18, 2022

CVE-2022-25602 on NVD →

Responsive Menu <= 4.1.7 - Missing Authorization Checks

medium

The Responsive Menu plugin for WordPress is vulnerable to authorization bypass due to missing authorization checks on various functions and nonce disclosure in versions up to, and including 4.1.7. This makes it possible for attackers to upload arbitrary files, delete themes, and change plugin settings.

CVSS:
6.3
Affected:
up to 4.1.8
Fixed in:
4.1.8
Disclosed:
Mar 16, 2022

CVE-2022-25602 on NVD →

Responsive Menu &#8211; Create Mobile-Friendly Menu [responsive-menu] >= 4.0.0 - <= 4.0.3

unknown

[en] In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an a...

Affected:
4.0.0 – 4.0.3
Fixed in:
4.0.3
Disclosed:
Apr 5, 2021

CVE-2021-24160 on NVD →

Responsive Menu &#8211; Create Mobile-Friendly Menu [responsive-menu] < 4.0.4

unknown

[en] In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of...

Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Apr 5, 2021

CVE-2021-24162 on NVD →

Responsive Menu &#8211; Create Mobile-Friendly Menu [responsive-menu] < 4.0.4

unknown

[en] In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.

Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Apr 5, 2021

CVE-2021-24161 on NVD →

Responsive Menu <= 4.0.3 - Cross-Site Request Forgery to Setting Modification

high

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the...

CVSS:
8.8
Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Feb 10, 2021

CVE-2021-24162 on NVD →

Responsive Menu <= 4.0.3 - Cross-Site Request Forgery to Arbitrary File Upload

high

In the Responsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.

CVSS:
8.8
Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Feb 10, 2021

CVE-2021-24161 on NVD →

Responsive Menu 4.0 - 4.0.3 - Authenticated Arbitrary File Upload

high

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attack...

CVSS:
8.8
Affected:
4.0 – 4.0.4
Fixed in:
4.0.4
Disclosed:
Feb 10, 2021

CVE-2021-24160 on NVD →

Responsive Menu &#8211; Create Mobile-Friendly Menu [responsive-menu] < 4.0.4

unknown

Authenticated Arbitrary File Upload vulnerability found by WordFence in WordPress Responsive Menu plugin (versions <= 4.0.3).

Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Feb 10, 2021

Responsive Menu &#8211; Create Mobile-Friendly Menu [responsive-menu] < 4.0.4

unknown

Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability found by WordFence in WordPress Responsive Menu plugin (versions <= 4.0.3).

Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Feb 10, 2021

Responsive Menu &#8211; Create Mobile-Friendly Menu [responsive-menu] < 4.0.4

unknown

Cross-Site Request Forgery (CSRF) leading to Setting Modification vulnerability found by WordFence in WordPress Responsive Menu plugin (versions <= 4.0.3).

Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Feb 10, 2021

Responsive Menu <= 3.1.3 - Cross-Site Request Forgery

high

The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.

CVSS:
8.8
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Jul 12, 2020

CVE-2017-18513 on NVD →

Responsive Menu &#8211; Create Mobile-Friendly Menu [responsive-menu] < 3.1.4

unknown

[en] The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Aug 14, 2019

CVE-2017-18513 on NVD →

Responsive Menu &#8211; Create Mobile-Friendly Menu [responsive-menu] < 3.1.4

unknown

Wordpress Responsive Menu plugin Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) Vulnerabilities. There's a lack of sanitization for saving the options in updateOptions() function, in the /app/Controllers/AdminController.php file. Also, a nonce is missing in the plugin's settings page. Update the plug...

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Jun 12, 2017

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database