Impact
The vulnerability is a stored cross‑site scripting flaw that allows an authenticated user with contributor or higher privileges to inject arbitrary scripts into WordPress pages via malicious shortcode attributes. Because the input is not properly sanitized and output is not escaped, an attacker can place JavaScript that will run in the browsers of any user who views the affected page. The attack can be used for defacement, credential theft, or social engineering against site visitors.
Affected Systems
The plugin affected is Responsive Plus – Elementor Templates & Starter Sites by cyberchimps. All releases up to and including version 3.5.3 are vulnerable. Sites using any of these versions are at risk; newer versions are not listed as affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4, indicating a moderate to high risk. EPSS information is not available, and it is not listed in the CISA KEV catalog. The likely attack vector requires authenticated contributor‑level access to the WordPress administration panel, where the user can insert a malicious shortcode into a page or post. Successful exploitation would execute the injected script in the context of any site visitor, enabling further attacks such as cookie theft, session hijacking, or malware delivery.
OpenCVE Enrichment