CVE-2023-45635 MEDIUM

CVE-2023-45635: WordPress Responsive Tabs plugin < 4.0.6 - HTML Content Injection vulnerability

Vendor Wp Darko
Product Responsive Tabs
Weakness CWE-80 · XSS · basic
Published June 4, 2024
Last update April 28, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs allows Code Injection.This issue affects Responsive Tabs: from n/a before 4.0.6.

Explanation of Vulnerability in Simple Terms

02Summary

Responsive Tabs for WordPress contains a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts. An attacker with low-level site access can modify tab content to execute JavaScript in other users' browsers, potentially compromising site functionality or stealing session data. Update to version 4.0.6 or later to fix this issue.

What an attacker can do

03Attacker Capabilities

Inject JavaScript code that runs in other users' browsers when they view affected tabs.

Potential impact on your site

04Site Impact

Malicious users with basic site access can deface content or steal admin session tokens.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege WordPress account (e.g., contributor or editor role).

Key dates

06Disclosure timeline

June 4, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE