Loading HuntDB...

GHSA-fjhj-x5j3-wcrf

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

Related CVEs

Key Information

GHSA ID
GHSA-fjhj-x5j3-wcrf
Published
May 24, 2022 5:46 PM
Last Modified
May 24, 2022 5:46 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 7, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.