Vulnerabilities > Expresstech > High

DATE CVE VULNERABILITY TITLE RISK
2021-04-05 CVE-2021-24162 Cross-Site Request Forgery (CSRF) vulnerability in Expresstech Responsive Menu
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings.
network
low complexity
expresstech CWE-352
8.8
2021-04-05 CVE-2021-24161 Cross-Site Request Forgery (CSRF) vulnerability in Expresstech Responsive Menu
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files.
network
low complexity
expresstech CWE-352
8.8
2021-04-05 CVE-2021-24160 Unrestricted Upload of File with Dangerous Type vulnerability in Expresstech Responsive Menu
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory.
network
low complexity
expresstech CWE-434
8.8
2019-08-14 CVE-2017-18513 Cross-Site Request Forgery (CSRF) vulnerability in Expresstech Responsive Menu
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
network
low complexity
expresstech CWE-352
8.8