CVE-2025-49856: WordPress Responsive Plus plugin <= 3.2.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in CyberChimps Responsive Plus allows Cross Site Request Forgery. This issue affects Responsive Plus: from n/a through 3.2.2.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Cross Site Request Forgery.This issue affects Responsive Plus: from n/a through <= 3.2.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49856?
CVE-2025-49856 is classified as a Cross-Site Request Forgery (CSRF) vulnerability affecting versions of CyberChimps Responsive Plus up to 3.2.2.
How do I fix CVE-2025-49856?
To fix CVE-2025-49856, update CyberChimps Responsive Plus to a version later than 3.2.2.
What are the potential risks of CVE-2025-49856?
CVE-2025-49856 can allow malicious users to perform unauthorized actions on behalf of authenticated users.
Who is affected by CVE-2025-49856?
Users of CyberChimps Responsive Plus and WordPress Responsive Plus versions up to 3.2.2 are affected by CVE-2025-49856.
What is Cross-Site Request Forgery in the context of CVE-2025-49856?
Cross-Site Request Forgery in CVE-2025-49856 allows attackers to perform actions on a website without the user's consent, exploiting the user's session.