CVE-2025-48335: WordPress Responsive Plus plugin <= 3.2.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in CyberChimps Responsive Plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Plus: from n/a through 3.2.0.
Other sources
Missing Authorization vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Plus: from n/a through <= 3.2.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48335?
CVE-2025-48335 is classified as a missing authorization vulnerability that can lead to unauthorized access due to incorrectly configured access control.
How do I fix CVE-2025-48335?
To fix CVE-2025-48335, you should update CyberChimps Responsive Plus to version 3.2.1 or later to address the access control issues.
Which versions of Responsive Plus are affected by CVE-2025-48335?
CVE-2025-48335 affects all versions of Responsive Plus up to and including 3.2.0.
What types of attacks can exploit CVE-2025-48335?
CVE-2025-48335 can be exploited through unauthorized access, where attackers may perform actions that should be restricted.
Is CVE-2025-48335 specific to any software vendor?
Yes, CVE-2025-48335 specifically affects the CyberChimps Responsive Plus and WordPress Responsive Plus plugins.