The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.4 via the 'remote_request' function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Feb 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cyberchimps
Cyberchimps responsive Addons |
|
CPEs | cpe:2.3:a:cyberchimps:responsive_addons:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Cyberchimps
Cyberchimps responsive Addons |
Tue, 18 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 15 Feb 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.4 via the 'remote_request' function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. | |
Title | Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme <= 3.1.4 - Authenticated (Contributor+) Blind Server-Side Request Forgery via remote_request | |
Weaknesses | CWE-918 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-18T19:35:46.616Z
Reserved: 2025-02-04T20:10:17.917Z
Link: CVE-2024-13834

Updated: 2025-02-18T16:41:40.256Z

Status : Analyzed
Published: 2025-02-15T15:15:23.423
Modified: 2025-02-24T12:37:18.957
Link: CVE-2024-13834

No data.