CVE · High

CVE-2021-24160 — Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] >= 4.0.0 - <= 4.0.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24160 Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] >= 4.0.0 - <= 4.0.3 Unrestricted Upload of File with Dangerous Type High 8.8 4.0.0–4.0.4 4.0.4 2021-02-10

CVE-2021-24160

The Responsive Menu plugin versions 4.0.0 through 4.0.3 contained a flaw allowing users with subscriber-level permissions to upload ZIP files with embedded malicious PHP code. When these archives were extracted to the /rmp-menu/ directory, the PHP files became accessible through the website's frontend, enabling arbitrary code execution and potential complete compromise of the WordPress installation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.