WP Responsive Tabs
WP Responsive Tabs has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for WP Responsive Tabs has a vendor fix available, so running the current release closes it.
All of these findings were reported by SOPROBRO. WP Responsive Tabs is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-13387WP Responsive Tabs <= 1.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

WP Responsive Tabs
Author
Fahad Mahmood
Author: Fahad Mahmood Project URI: http://androidbubble.com/blog/wordpress/plugins/wprtp Demo URI: http://demo.wethebrains.com/wp-responsive-tabs License: GPL 3. See License below for copyright jots and tittles. WP Responsive Tabs allows you to create tabs with shortcodes in post/page and anywhere in your content. WooCommerce and eCommerce related taxonomies can be added in tabs. Now you can add WP Docs directories with shortcodes in WP Responsive Tabs as well. Overview Add tabs with shorcodes Shortcodes for eCommerce Shortcodes for WooCommerce Compatible with WordPress plugin WP Docs Shortcode: License This WordPress plugin is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or any later version. This WordPress plugin is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this WordPress plugin. If not, see http://www.gnu.org/licenses/gpl-2.0.html.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C