Impact
The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to change the settings of the Responsive Plus plugin. The flaw stems from improper validation of state‑changing requests, enabling a malicious actor to force a legitimate user to modify configuration options without their consent. The resulting impact is an elevated privilege scenario where attackers can alter plugin behavior.
Affected Systems
CyberChimps Responsive Plus plugin versions through and including 3.2.2 are affected. Any WordPress installation that has the plugin installed in these versions is vulnerable. The vulnerability applies to all environments where the plugin is active, regardless of operating system or hosting model.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, reflecting the need for authenticated access to achieve the exploit. The EPSS score of <1% suggests the probability of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker needs a target user with sufficient permissions, such as an authenticated WordPress administrator or editor, to trigger the CSRF, and no additional system‑level privileges are required.
OpenCVE Enrichment
EUVD