Stored Cross-Site Scripting Vulnerability in Responsive Check Plugin for WordPress
CVE-2026-8844
6.4MEDIUM
What is CVE-2026-8844?
The Responsive Check plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting (XSS) via the 'rspcheck' shortcode. This flaw arises from inadequate input sanitization and output escaping within the 'url' and 'button' attributes in the rspc_check_shortcode() function. With this vulnerability, authenticated users who have contributor-level access or higher can inject malicious web scripts. These scripts execute when unsuspecting users access pages that incorporate the compromised shortcode, which can lead to the exploitation of user sessions and manipulation of web content.
Affected Version(s)
Responsive Check 0 <= 0.0.3