CVE-2025-24647
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-24647 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the WooCommerce Cloak Affiliate Links plugin on datafeedr.com. This issue enables attackers to craft malicious requests that, if successfully executed by an affected user, can force the user to perform unwanted actions on the website, such as changing account settings or making unauthorized purchases. The CSRF vulnerability impacts versions of the plugin ranging from not available to 1.0.35. Updating to the latest, secure version of the plugin is strongly recommended to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.