Sceawere
Vulnerability Detail
CVE-2026-15795UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Responsive Plus
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 3h ago
- Vendor
- cyberchimps
- Product
- Responsive Starter Templates – Elementor Templates & Starter Sites
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-03T07:16:47.583Z",
"pubdate": "2026-10-03T07:16:47.583Z",
"executiveSummary": "The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability existing in all versions up to and including 3.5.3.\nThe vulnerability arises from the application's failure to adequately sanitize user-supplied input or implement robust output escaping within its shortcode attributes.\nThis security flaw allows authenticated users with contributor-level privileges or higher to inject malicious JavaScript payloads directly into the plugin's shortcode parameters.\nWhen a user or administrator subsequently views a page containing the compromised shortcode, the stored malicious script executes within the context of the victim's browser session.\nThis facilitates a range of malicious activities, including session hijacking, unauthorized actions performed on behalf of the victim, or the redirection of users to malicious third-party domains.\nGiven that the exploit requires only contributor-level access, the threat landscape is significantly elevated for multi-author WordPress environments, where untrusted users can leverage this flaw to compromise the integrity of the administrative interface.",
"technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting, stemming from improper input handling within the Responsive Plus plugin’s shortcode parsing logic.\nThe root cause of this issue is the application’s failure to perform context-aware output encoding or strict input sanitization on attributes processed by shortcode handlers before rendering them in the Document Object Model (DOM).\nAn attacker possessing contributor-level privileges can supply crafted JavaScript within these attributes. When the WordPress shortcode engine processes the page content, the plugin retrieves these unfiltered attributes and embeds them directly into the rendered HTML output.\nThe exploitation flow proceeds as follows: First, the attacker identifies a shortcode provided by Responsive Plus that permits attribute configuration. Second, the attacker embeds a malicious script payload (e.g., <script>alert(document.cookie)</script>) within one of the supported attributes. Third, upon saving the post or page, this malicious string is persisted in the WordPress database.\nWhen a victim, such as a site administrator, visits the affected page, the server renders the stored malicious script into the HTML body. The browser interprets this payload as legitimate code and executes it within the scope of the current session.\nBecause the payload runs in the browser of the viewer, the attacker can bypass Same-Origin Policy (SOP) restrictions to perform unauthorized requests, modify page content, or exfiltrate sensitive session identifiers and cookies.\nThis vulnerability is particularly impactful because it does not require external network exposure beyond the standard authenticated access already granted to contributors. The lack of validation ensures that any script successfully stored will trigger automatically upon rendering, facilitating persistent unauthorized code execution."
}