Description
The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-10-03
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw that allows an authenticated user with contributor or higher privileges to inject arbitrary scripts into WordPress pages via malicious shortcode attributes. Because the input is not properly sanitized and output is not escaped, an attacker can place JavaScript that will run in the browsers of any user who views the affected page. The attack can be used for defacement, credential theft, or social engineering against site visitors.

Affected Systems

The plugin affected is Responsive Plus – Elementor Templates & Starter Sites by cyberchimps. All releases up to and including version 3.5.3 are vulnerable. Sites using any of these versions are at risk; newer versions are not listed as affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.4, indicating a moderate to high risk. EPSS information is not available, and it is not listed in the CISA KEV catalog. The likely attack vector requires authenticated contributor‑level access to the WordPress administration panel, where the user can insert a malicious shortcode into a page or post. Successful exploitation would execute the injected script in the context of any site visitor, enabling further attacks such as cookie theft, session hijacking, or malware delivery.

Generated by OpenCVE AI on October 3, 2026 at 09:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Responsive Plus – Elementor Templates & Starter Sites plugin to the latest version (>= 3.5.4) which removes the stored XSS weakness.
  • If an upgrade is not immediately possible, deactivate the plugin on affected sites to prevent exploitation until a fix is applied.
  • Review and sanitize existing content: remove or edit any posts or pages containing the vulnerable shortcode attributes, and restrict contributor‑level users from adding or editing shortcodes until the vulnerability is patched.

Generated by OpenCVE AI on October 3, 2026 at 09:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Responsive Plus <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:42.767Z

Reserved: 2026-07-14T19:40:29.577Z

Link: CVE-2026-15795

cve-icon Vulnrichment

Updated: 2026-10-03T15:38:56.174Z

cve-icon NVD

Status : Received

Published: 2026-10-03T07:16:47.583

Modified: 2026-10-03T16:16:36.160

Link: CVE-2026-15795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T09:30:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')