CVE-2025-57934: WordPress LWS Affiliation Plugin <= 2.3.6 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Aurélien LWS LWS Affiliation allows Cross Site Request Forgery. This issue affects LWS Affiliation: from n/a through 2.3.6.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Aurélien LWS LWS Affiliation lws-affiliation allows Cross Site Request Forgery.This issue affects LWS Affiliation: from n/a through <= 2.3.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57934?
CVE-2025-57934 is classified as a high-severity Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-57934?
To fix CVE-2025-57934, update the LWS Affiliation plugin to version 2.3.7 or later.
Which versions of Aurélien LWS LWS Affiliation are affected by CVE-2025-57934?
Versions from n/a up to and including 2.3.6 of Aurélien LWS LWS Affiliation are affected by CVE-2025-57934.
What is the nature of the vulnerability described in CVE-2025-57934?
CVE-2025-57934 allows attackers to exploit the application using Cross-Site Request Forgery, potentially compromising user actions.
Is CVE-2025-57934 specific to any platforms?
CVE-2025-57934 affects both the Aurélien LWS LWS Affiliation and the WordPress LWS Affiliation Plugin.