Record summary

CVE-2025-15488 has a selected CVSS score of 6.5 (medium).

Description

The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software allowing unauthenticated users to execute the update_responsive_woo_free_shipping_left_shortcode AJAX action that does not properly validate the content_rech_data parameter before processing it as a shortcode.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 30, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 26, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Responsive Plus

Default status: unaffected

CVE ListBefore 3.4.3affected

References

2