ExpressTech Vulnerabilities and Affected Products
Vulnerabilities associated with Responsive Menu Pro.
Products
Clear product- Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker13 vulnerabilities
- Quiz And Survey Master12 vulnerabilities
- Quiz And Survey Master (WordPress plugin)9 vulnerabilities
- quiz_and_survey_master8 vulnerabilities
- Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress3 vulnerabilities
- Responsive Menu Pro3 vulnerabilities
- Responsive Menu – Create Mobile-Friendly Menu3 vulnerabilities
- Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker1 vulnerability
- Responsive Menu (WordPress plugin)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-24162HIGH | Responsive Menu < 4.0.4 - CSRF to Settings UpdateIn the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site. CWE-352Apr 5, 2021 | CVSS8.8v3.1 | EPSS0.796% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24160HIGH | Responsive Menu 4.0.0 - 4.0.3 - Authenticated Arbitrary File UploadIn the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site. CWE-434Apr 5, 2021 | CVSS8.8v3.1 | EPSS8.2% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24161HIGH | Responsive Menu < 4.0.4 - CSRF to Arbitrary File UploadIn the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site. CWE-352Apr 5, 2021 | CVSS8.8v3.1 | EPSS1.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |