CVE-2025-24647

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 24, 2025
CWE ID 352

Summary

CVE-2025-24647 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the WooCommerce Cloak Affiliate Links plugin on datafeedr.com. This issue enables attackers to craft malicious requests that, if successfully executed by an affected user, can force the user to perform unwanted actions on the website, such as changing account settings or making unauthorized purchases. The CSRF vulnerability impacts versions of the plugin ranging from not available to 1.0.35. Updating to the latest, secure version of the plugin is strongly recommended to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share