First published: Tue Jan 21 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in anyroad.com AnyRoad allows Cross Site Request Forgery. This issue affects AnyRoad: from n/a through 1.3.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
AnyRoad | <=1.3.2 | |
WordPress Anyroad Plugin | <=1.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23996 is classified as a Cross-Site Request Forgery (CSRF) vulnerability with potential for moderate impact.
To fix CVE-2025-23996, update AnyRoad to version 1.3.3 or later.
CVE-2025-23996 affects AnyRoad versions up to and including 1.3.2 and the AnyRoad plugin for WordPress.
Yes, CVE-2025-23996 can allow attackers to perform unauthorized actions on behalf of authenticated users.
If you cannot update, consider disabling the AnyRoad plugin or implementing additional security measures to mitigate CSRF attacks.