CVE-2025-59568: WordPress Zoho Flow Plugin <= 2.14.1 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Zoho Flow Zoho Flow allows Cross Site Request Forgery. This issue affects Zoho Flow: from n/a through 2.14.1.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Zoho Flow Zoho Flow zoho-flow allows Cross Site Request Forgery.This issue affects Zoho Flow: from n/a through <= 2.14.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59568?
CVE-2025-59568 is classified as a Cross-Site Request Forgery (CSRF) vulnerability and poses a moderate risk to affected systems.
How do I fix CVE-2025-59568?
To remediate CVE-2025-59568, upgrade Zoho Flow to version 2.14.2 or later.
What versions of Zoho Flow are affected by CVE-2025-59568?
CVE-2025-59568 affects all versions of Zoho Flow from n/a to 2.14.1.
Is Zoho WordPress Plugin for Flow vulnerable to CVE-2025-59568?
Yes, the Zoho WordPress Plugin for Flow is also vulnerable to CVE-2025-59568 up to version 2.14.1.
What types of attacks can CVE-2025-59568 enable?
CVE-2025-59568 can enable attackers to perform unauthorized actions on behalf of authenticated users without their consent.