CVE-2025-31408: WordPress Zoho Flow plugin <= 2.13.3 - Broken Access Control vulnerability
Published Apr 1, 2025
·Updated
Missing Authorization vulnerability in Zoho Flow Zoho Flow zoho-flow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho Flow: from n/a through <= 2.13.3.
Affected Software
2 affected components
Zoho Zoho Flow<=2.13.3
Zoho Zoho Flow WordPress plugin<=2.13.3
Event History
Apr 1, 2025
CVE Published
via MITRE·01:07 PM
Data Sourced
via MITRE·01:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-31408?
The severity of CVE-2025-31408 is critical due to the risk of unauthorized access caused by missing authorization controls.
2
How do I fix CVE-2025-31408?
To fix CVE-2025-31408, upgrade Zoho Flow to version 2.13.4 or later to ensure proper access control.
3
What versions of Zoho Flow are affected by CVE-2025-31408?
CVE-2025-31408 affects Zoho Flow versions from n/a through 2.13.3.
4
Is the WordPress Zoho Flow plugin vulnerable to CVE-2025-31408?
Yes, the WordPress Zoho Flow plugin versions up to 2.13.3 are vulnerable to CVE-2025-31408.
5
What type of vulnerability is CVE-2025-31408?
CVE-2025-31408 is categorized as a Missing Authorization vulnerability.