WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Responsive Menu safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Responsive Menu WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: responsive-menu

Maintenance status

Known vulnerabilities

5 known CVEs on file for Responsive Menu. Reported between 2017 and 2022.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-25602 Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] < 4.1.8 Exposure of Sensitive Information to an Unauthorized Actor High 8.8 < 4.1.8 4.1.8 2022-03-16
CVE-2021-24160 Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] >= 4.0.0 - <= 4.0.3 Unrestricted Upload of File with Dangerous Type High 8.8 4.0.0–4.0.3 4.0.3 2021-02-10
CVE-2021-24162 Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] < 4.0.4 Cross-Site Request Forgery (CSRF) High 8.8 < 4.0.4 4.0.4 2021-02-10
CVE-2021-24161 Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] < 4.0.4 Cross-Site Request Forgery (CSRF) High 8.8 < 4.0.4 4.0.4 2021-02-10
Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] < 4.0.4 Unknown < 4.0.4 4.0.4 2021-02-10
Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] < 4.0.4 Unknown < 4.0.4 4.0.4 2021-02-10
Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] < 4.0.4 Unknown < 4.0.4 4.0.4 2021-02-10
CVE-2017-18513 Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] < 3.1.4 Cross-Site Request Forgery (CSRF) High 8.8 < 3.1.4 3.1.4 2019-08-14

CVE-2022-25602

The plugin is missing authorisation on multiple of its AJAX actions (such as save_menu_global_settings), and relying on CSRF nonces which are disclosed to any authenticated users. As a result, it could allow them to call the affected actions and lead to arbitrary file upload, theme deletion as well as plugin settings update issues

Source: WPScan

CVE-2021-24160

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

Source: CVE.org

CVE-2021-24162

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.

Source: CVE.org

CVE-2021-24161

In the Responsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.

Source: Wordfence

Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] < 4.0.4

Authenticated Arbitrary File Upload vulnerability found by WordFence in WordPress Responsive Menu plugin (versions <= 4.0.3).

Source: Patchstack

Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] < 4.0.4

Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability found by WordFence in WordPress Responsive Menu plugin (versions <= 4.0.3).

Source: Patchstack

Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] < 4.0.4

Cross-Site Request Forgery (CSRF) leading to Setting Modification vulnerability found by WordFence in WordPress Responsive Menu plugin (versions <= 4.0.3).

Source: Patchstack

CVE-2017-18513

The Responsive Menu – Create Mobile-Friendly Menu WordPress plugin was affected by a XSS and CSRF security vulnerability.

Source: WPScan

+ 1 more known vulnerability
CVE Vulnerability Type Severity Affected Fixed in Published Status
Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] < 3.1.4 Unknown < 3.1.4 3.1.4 2017-06-12

Responsive Menu – Create Mobile-Friendly Menu [responsive-menu] < 3.1.4

Wordpress Responsive Menu plugin Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) Vulnerabilities. There's a lack of sanitization for saving the options in updateOptions() function, in the /app/Controllers/AdminController.php file. Also, a nonce is missing in the plugin's settings page. Update the plugin.

Source: Patchstack

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.