First published: Tue Apr 22 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit allows Cross Site Request Forgery. This issue affects affiliate-toolkit: from n/a through 3.7.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Servit Software Solutions Affiliate-toolkit | <=3.7.3 | |
WordPress affiliate-toolkit | <=3.7.3 |
Update the WordPress affiliate-toolkit plugin to the latest available version (at least 3.7.4).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46231 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which poses a significant security risk.
To fix CVE-2025-46231, upgrade your SERVIT Software Solutions affiliate-toolkit to version 3.7.4 or later.
CVE-2025-46231 affects all versions of the affiliate-toolkit from the initial release up to and including version 3.7.3.
CVE-2025-46231 involves Cross-Site Request Forgery (CSRF), allowing attackers to perform unauthorized actions on behalf of a user.
If an immediate update isn’t possible, consider implementing CSRF tokens in your forms to mitigate the risk of CVE-2025-46231.