First published: Tue Apr 01 2025(Updated: )
Missing Authorization vulnerability in Zoho Flow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho Flow: from n/a through 2.13.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho Flow | >=2.13.3 | |
Zoho Flow | <=2.13.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-31408 is critical due to the risk of unauthorized access caused by missing authorization controls.
To fix CVE-2025-31408, upgrade Zoho Flow to version 2.13.4 or later to ensure proper access control.
CVE-2025-31408 affects Zoho Flow versions from n/a through 2.13.3.
Yes, the WordPress Zoho Flow plugin versions up to 2.13.3 are vulnerable to CVE-2025-31408.
CVE-2025-31408 is categorized as a Missing Authorization vulnerability.