plugin

Responsive Tabs Vulnerabilities

10 known security issues reported for the Responsive Tabs WordPress plugin. Most recent disclosed Jul 30, 2024.

5 medium

Running Responsive Tabs on your site? Check whether your installed version is affected.

Scan your site free

Responsive Tabs [responsive-tabs] < 4.0.11

unknown

[en] The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 4.0.11
Fixed in:
4.0.11
Disclosed:
Jul 30, 2024

CVE-2024-4096 on NVD →

Responsive Tabs <= 4.0.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Tab' titles in all versions up to, and including, 4.0.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary...

CVSS:
6.4
Affected:
up to 4.0.10
Fixed in:
4.0.11
Disclosed:
Jul 9, 2024

CVE-2024-4096 on NVD →

Responsive Tabs [responsive-tabs] < 4.0.6

unknown

[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs allows Code Injection.This issue affects Responsive Tabs: from n/a before 4.0.6.

Affected:
up to 4.0.6
Fixed in:
4.0.6
Disclosed:
Jun 4, 2024

CVE-2023-45635 on NVD →

Responsive Tabs [responsive-tabs] < 4.0.7

unknown

[en] The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 4.0.7
Fixed in:
4.0.7
Disclosed:
Apr 15, 2024

CVE-2024-1846 on NVD →

Responsive Tabs [responsive-tabs] < 4.0.7

unknown
Affected:
up to 4.0.7
Fixed in:
4.0.7
Disclosed:
Apr 9, 2024

CVE-2024-3514 on NVD →

Responsive Tabs <= 4.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tabs_color value in all versions up to, and including, 4.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level ac...

CVSS:
6.4
Affected:
up to 4.0.6
Fixed in:
4.0.7
Disclosed:
Mar 25, 2024

CVE-2024-1846 on NVD →

Carousel Slider <= 2.2.6 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Responsive Tabs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Slides Per View parameter in all versions up to, and including, 2.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
5.5
Affected:
up to 2.2.6
Fixed in:
2.2.7
Disclosed:
Mar 25, 2024

CVE-2024-1712 on NVD →

Responsive Tabs < 4.0.6 - Authenticated (Contributor+) Content Injection

medium

The Responsive Tabs plugin for WordPress is vulnerable to Arbitrary Content Injection in versions prior to 4.0.6. This vulnerability makes it possible for authenticated attackers, with contributor-level permissions and above, to inject new content onto the website, possibly through the manipulation of posts to create n...

CVSS:
4.3
Affected:
up to 4.0.6
Fixed in:
4.0.6
Disclosed:
Oct 11, 2023

CVE-2023-45635 on NVD →

Responsive Tabs <= 4.0.5 - Authenticated Stored Cross-Site Scripting

medium

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5

CVSS:
4.8
Affected:
up to 4.0.5
Fixed in:
4.0.6
Disclosed:
Apr 11, 2022

CVE-2021-36893 on NVD →

Responsive Tabs [responsive-tabs] < 4.0.6

unknown

[en] Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress plugin) <= 4.0.5

Affected:
up to 4.0.6
Fixed in:
4.0.6
Disclosed:
Apr 11, 2022

CVE-2021-36893 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database