nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-15488 CVE-2025-15488
MEDIUM
Responsive Plus < 3.4.3 - Unauthenticated Arbitrary Shortcode Execution
Record summary
CVE-2025-15488 has a selected CVSS score of 6.5 (medium).
Description
The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software allowing unauthenticated users to execute the update_responsive_woo_free_shipping_left_shortcode AJAX action that does not properly validate the content_rech_data parameter before processing it as a shortcode.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 30, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 26, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Responsive PlusBrowse CyberChimps / Responsive Plus | VulnCheck | Version data not supplied | |
Responsive PlusDefault status: unaffected | CVE List | Before 3.4.3 | affected |
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/80ce0f88-3065-48c4-a491-b70e067ce4d7