VYPR
Medium severity4.3NVD Advisory· Published Sep 22, 2025· Updated Apr 23, 2026

CVE-2025-59568

CVE-2025-59568

Description

Cross-Site Request Forgery (CSRF) vulnerability in Zoho Flow Zoho Flow zoho-flow allows Cross Site Request Forgery.This issue affects Zoho Flow: from n/a through <= 2.14.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-Site Request Forgery (CSRF) vulnerability in Zoho Flow WordPress plugin up to 2.14.1 allows attackers to force privileged users into unintended actions.

Vulnerability

Overview

The Zoho Flow plugin for WordPress (versions up to and including 2.14.1) contains a Cross-Site Request Forgery (CSRF) vulnerability [1]. This flaw arises from insufficient validation of request origins, allowing an attacker to craft malicious requests that are executed in the context of an authenticated administrator.

Exploitation

Details

To exploit this vulnerability, an attacker must trick a logged-in user with elevated privileges (such as an administrator) into clicking a crafted link or visiting a malicious page [1]. No direct authentication is required for the attacker; instead, the attack leverages the victim's active session to perform unauthorized actions.

Impact

Successful exploitation enables an attacker to force the victim to perform unintended actions within the Zoho Flow plugin, such as modifying configurations, creating or deleting flows, or altering settings [1]. This could lead to disruption of service or unauthorized data manipulation.

Mitigation

The vulnerability has been addressed in version 2.14.2 of the plugin [1]. Users are strongly advised to update immediately. Patchstack also recommends enabling auto-updates for vulnerable plugins to prevent future exploitation [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.