CVE-2025-47486
Description
Missing Authorization vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Plus: from n/a through <= 3.1.9.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Responsive Plus plugin below 3.2.0 has a broken access control flaw allowing unauthenticated access to restricted functionality.
Vulnerability
Overview
The Responsive Plus WordPress plugin (by CyberChimps) versions n/a through 3.1.9 contain a missing authorization vulnerability in its responsive-add-ons component. This issue allows unauthenticated users to access functionality that should be properly constrained by access control lists (ACLs) [1].
Exploitation
Details
The vulnerability is categorized as a broken access control defect, meaning the plugin fails to perform adequate authorization or nonce token checks on certain functions. An attacker can exploit this by sending crafted requests to the affected endpoint without needing any authentication, enabling them to trigger actions or access features intended for higher-privileged users [1].
Impact
Successful exploitation enables an unprivileged attacker to access restricted functionality within the plugin. While the severity is rated Medium (CVSS 5.3) and the vendor describes the impact as low severity and unlikely to be exploited, mass-exploit campaigns have been observed targeting similar vulnerabilities to attack thousands of websites simultaneously [1].
Mitigation
The vulnerability is fixed in version 3.2.0 of the Responsive Plus plugin. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. If updating is not possible, contacting a hosting provider or web developer for assistance is recommended as a workaround [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <= 3.1.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.