CyberChimps Vulnerabilities and Affected Products
Vulnerabilities associated with Responsive Plus.
Products
Clear product- Responsive Addons for Elementor – Free Elementor Addons, Kits and Elementor Templates5 vulnerabilities
- Responsive Blocks5 vulnerabilities
- Responsive Blocks – Page Builder for Blocks & Patterns4 vulnerabilities
- Responsive Plus4 vulnerabilities
- Responsive Addons for Elementor3 vulnerabilities
- Responsive2 vulnerabilities
- Responsive Plus – Elementor Templates & Starter Sites2 vulnerabilities
- Responsive Blocks – WordPress Gutenberg Blocks1 vulnerability
- Responsive Mobile1 vulnerability
- Responsive theme for WordPress1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-15488MEDIUM | Responsive Plus < 3.4.3 - Unauthenticated Arbitrary Shortcode ExecutionThe Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software allowing unauthenticated users to execute the update_responsive_woo_free_shipping_left_shortcode AJAX action that does not properly validate the content_rech_data parameter before processing it as a shortcode. CWE-863Mar 26, 2026 | CVSS6.5v3.1 | EPSS0.323% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49856MEDIUM | WordPress Responsive Plus plugin <= 3.2.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Cross Site Request Forgery.This issue affects Responsive Plus: from n/a through <= 3.2.2. CWE-352Jun 17, 2025 | CVSS4.3v3.1 | EPSS0.121% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-48335MEDIUM | WordPress Responsive Plus plugin <= 3.2.0 - Broken Access Control vulnerabilityMissing Authorization vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Plus: from n/a through <= 3.2.0. CWE-862Jun 6, 2025 | CVSS5.4v3.1 | EPSS0.215% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-47486MEDIUM | WordPress Gutenberg & Elementor Templates Importer For Responsive plugin <= 3.1.9 - Broken Access Control VulnerabilityMissing Authorization vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Plus: from n/a through <= 3.1.9. CWE-862May 7, 2025 | CVSS5.3v3.1 | EPSS0.32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |