Cross-Site Request Forgery Vulnerability in Responsive Plus by CyberChimps
CVE-2025-49856

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2025

What is CVE-2025-49856?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Responsive Plus plugin developed by CyberChimps. This flaw allows attackers to execute unauthorized actions on behalf of the user, potentially leading to significant security breaches. The vulnerability affects all versions of Responsive Plus from n/a to 3.2.2, and it can enable malicious actors to manipulate settings and perform actions that the authenticated user did not intend. Website administrators should take immediate action to mitigate this risk by updating to the latest version or implementing security measures to safeguard against CSRF attacks.

Affected Version(s)

Responsive Plus <= 3.2.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chazz Wolcott (Patchstack)
.