Description
Missing Authorization vulnerability in Zoho Flow Zoho Flow zoho-flow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho Flow: from n/a through <= 2.13.3.
Published: 2025-04-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization check in the Zoho Flow WordPress plugin, identified as CWE‑862. It allows users who are not properly authenticated or authorized to perform actions, read data, or alter settings that should be restricted to administrators. Consequently, attackers could gain unauthorized administrative privileges or access sensitive data within the WordPress site and the connected Zoho Flow system. This flaw directly undermines confidentiality, integrity, and potentially availability if administrative actions are abused.

Affected Systems

WordPress installations that have the Zoho Flow plugin v2.13.3 or earlier installed are affected. The issue spans all versions from the earliest released plugin version through v2.13.3.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of <1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could exploit exposed plugin endpoints without proper authentication, potentially via a remote web request that bypasses role checks. The lack of authorization enforcement is the root weakness, and the risk to a site that has the vulnerable plugin enabled is moderate but could be amplified if the plugin manages sensitive data or integrates with external services.

Generated by OpenCVE AI on May 1, 2026 at 02:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Zoho Flow WordPress plugin to the latest version that includes the access control fix.
  • If upgrading is not possible, disable or remove the plugin to eliminate the vulnerability.
  • Apply temporary restrictions on the plugin’s endpoints (e.g., via web server rules or a WAF) so that only authenticated administrators can access them.

Generated by OpenCVE AI on May 1, 2026 at 02:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9296 Missing Authorization vulnerability in Zoho Flow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho Flow: from n/a through 2.13.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Zoho Flow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho Flow: from n/a through 2.13.3. Missing Authorization vulnerability in Zoho Flow Zoho Flow zoho-flow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho Flow: from n/a through <= 2.13.3.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 01 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Zoho Flow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho Flow: from n/a through 2.13.3.
Title WordPress Zoho Flow plugin <= 2.13.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:06.042Z

Reserved: 2025-03-28T10:59:52.730Z

Link: CVE-2025-31408

cve-icon Vulnrichment

Updated: 2025-04-01T15:21:43.459Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T13:15:41.037

Modified: 2026-04-23T15:27:46.390

Link: CVE-2025-31408

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T02:45:06Z

Weaknesses