CVE-2025-46231: WordPress affiliate-toolkit plugin <= 3.7.3 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Cross Site Request Forgery.This issue affects affiliate-toolkit: from n/a through <= 3.7.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46231?
CVE-2025-46231 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which poses a significant security risk.
How do I fix CVE-2025-46231?
To fix CVE-2025-46231, upgrade your SERVIT Software Solutions affiliate-toolkit to version 3.7.4 or later.
What versions of affiliate-toolkit are affected by CVE-2025-46231?
CVE-2025-46231 affects all versions of the affiliate-toolkit from the initial release up to and including version 3.7.3.
What type of attack does CVE-2025-46231 involve?
CVE-2025-46231 involves Cross-Site Request Forgery (CSRF), allowing attackers to perform unauthorized actions on behalf of a user.
Is there a workaround for CVE-2025-46231 if I can’t update immediately?
If an immediate update isn’t possible, consider implementing CSRF tokens in your forms to mitigate the risk of CVE-2025-46231.