First published: Tue Jan 07 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Jason Keeley, Bryan Nielsen Affiliate Disclosure Statement allows Cross Site Request Forgery.This issue affects Affiliate Disclosure Statement: from n/a through 0.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Affiliate Disclosure Statement plugin | <=0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2025-22552 vulnerability is classified as a Cross-Site Request Forgery (CSRF) issue.
CVE-2025-22552 allows an attacker to perform unauthorized actions on behalf of a user, potentially compromising account security.
To address CVE-2025-22552, update the Affiliate Disclosure Statement plugin to a version greater than 0.3 or implement security measures to prevent CSRF attacks.
CVE-2025-22552 affects the Affiliate Disclosure Statement plugin from n/a up to version 0.3.
The vendor associated with CVE-2025-22552 is WordPress, specifically related to the Affiliate Disclosure Statement plugin.