PatchSiren cyber security CVE debrief
CVE-2026-15795 cyberchimps CVE debrief
The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. As a result, attackers may compromise page integrity, leading to potential user exploitation. The vulnerability's impact is moderate, with a CVSS score of 6.4, indicating a medium severity level. Defenders should assess exposure and prioritize
- Vendor
- cyberchimps
- Product
- Responsive Starter Templates – Elementor Templates & Starter Sites
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
WordPress administrators, security teams, and developers using the Responsive Plus plugin should assess exposure and prioritize remediation. This is particularly important for installations with contributor-level access or above, as attackers with such access can exploit this vulnerability. Security teams should review the vulnerability's impact on their organization's WordPress deployments and ensure that necessary mitigations are implemented. Developers
Why it matters
CVE-2026-15795 is a Stored Cross-Site Scripting vulnerability in the Responsive Plus plugin for WordPress. While exploitation details are limited, defenders should assess exposure and prioritize remediation for WordPress installations using this plugin, especially those with contributor-level access or above.
- Attackers may inject malicious scripts, potentially leading to user exploitation
- Compromised pages may execute arbitrary scripts, affecting site integrity
- Remediation priority is moderate due to the medium CVSS score
Technical summary
The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.5.3. This allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is caused by insufficient input sanitization and output escaping. The CVSS score of 6.4 indicates a medium severity level. To defend against this vulnerability, it is essential to assess exposure and prioritize remediation for WordPress installations using the Responsive Plus plugin, particularly those with contributor-level
Defensive priority
Assess exposure and prioritize remediation for WordPress installations using the Responsive Plus plugin, particularly those with contributor-level access or above.
Recommended defensive actions
- Assess WordPress installations for the Responsive Plus plugin version 3.5.3 or earlier
- Prioritize remediation for installations with contributor-level access or above
- Verify input sanitization and output escaping for shortcode attributes
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score. However, the corpus lacks specific information on exploitation, victims, or business impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-15795 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-15795
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-15795 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15795
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/responsive-add-ons/tags/3.5.2/includes/customizer/helper.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.