CVE-2026-15795: Responsive Plus <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to WordPress with at least Contributor-level access. Exploitation does not require user interaction from the attacker.
What happens after malicious shortcode attributes are saved?
Arbitrary web scripts can be stored in a page and execute when another user accesses that injected page. The issue can affect confidentiality and integrity, while no availability impact is indicated.
Which versions are affected?
All Responsive Plus – Elementor Templates & Starter Sites versions through 3.5.3 are affected. The provided data does not identify a fixed version.