Responsive Tabs [responsive-tabs] < 4.0.11
unknown
[en] The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 4.0.11
- Fixed in:
- 4.0.11
- Disclosed:
- Jul 30, 2024
CVE-2024-4096 on NVD →
Responsive Tabs <= 4.0.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Tab' titles in all versions up to, and including, 4.0.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary...
- CVSS:
- 6.4
- Affected:
- up to 4.0.10
- Fixed in:
- 4.0.11
- Disclosed:
- Jul 9, 2024
CVE-2024-4096 on NVD →
Responsive Tabs [responsive-tabs] < 4.0.6
unknown
[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs allows Code Injection.This issue affects Responsive Tabs: from n/a before 4.0.6.
- Affected:
- up to 4.0.6
- Fixed in:
- 4.0.6
- Disclosed:
- Jun 4, 2024
CVE-2023-45635 on NVD →
Responsive Tabs [responsive-tabs] < 4.0.7
unknown
[en] The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 4.0.7
- Fixed in:
- 4.0.7
- Disclosed:
- Apr 15, 2024
CVE-2024-1846 on NVD →
Responsive Tabs [responsive-tabs] < 4.0.7
unknown
- Affected:
- up to 4.0.7
- Fixed in:
- 4.0.7
- Disclosed:
- Apr 9, 2024
CVE-2024-3514 on NVD →
Responsive Tabs <= 4.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tabs_color value in all versions up to, and including, 4.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level ac...
- CVSS:
- 6.4
- Affected:
- up to 4.0.6
- Fixed in:
- 4.0.7
- Disclosed:
- Mar 25, 2024
CVE-2024-1846 on NVD →
Carousel Slider <= 2.2.6 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Responsive Tabs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Slides Per View parameter in all versions up to, and including, 2.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 5.5
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.7
- Disclosed:
- Mar 25, 2024
CVE-2024-1712 on NVD →
Responsive Tabs < 4.0.6 - Authenticated (Contributor+) Content Injection
medium
The Responsive Tabs plugin for WordPress is vulnerable to Arbitrary Content Injection in versions prior to 4.0.6. This vulnerability makes it possible for authenticated attackers, with contributor-level permissions and above, to inject new content onto the website, possibly through the manipulation of posts to create n...
- CVSS:
- 4.3
- Affected:
- up to 4.0.6
- Fixed in:
- 4.0.6
- Disclosed:
- Oct 11, 2023
CVE-2023-45635 on NVD →
Responsive Tabs <= 4.0.5 - Authenticated Stored Cross-Site Scripting
medium
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5
- CVSS:
- 4.8
- Affected:
- up to 4.0.5
- Fixed in:
- 4.0.6
- Disclosed:
- Apr 11, 2022
CVE-2021-36893 on NVD →
Responsive Tabs [responsive-tabs] < 4.0.6
unknown
[en] Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5
- Affected:
- up to 4.0.6
- Fixed in:
- 4.0.6
- Disclosed:
- Apr 11, 2022
CVE-2021-36893 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database