๐Ÿ” CVE Alert

CVE-2025-15488

MEDIUM 6.5

Responsive Plus < 3.4.3 - Unauthenticated Arbitrary Shortcode Execution

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
6th

The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software allowing unauthenticated users to execute the update_responsive_woo_free_shipping_left_shortcode AJAX action that does not properly validate the content_rech_data parameter before processing it as a shortcode.

Vendor unknown
Product responsive plus
Published Mar 26, 2026
Last Updated Mar 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown responsive plus

Be the first to know when new medium vulnerabilities affecting unknown responsive plus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Responsive Plus
0 < 3.4.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/80ce0f88-3065-48c4-a491-b70e067ce4d7/

Credits

Alex Tselevich (nos3curity) WPScan