Server-Side Request Forgery Vulnerability in Skimlinks Affiliate Marketing Tool
CVE-2025-57943

4.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-57943?

The Skimlinks Affiliate Marketing Tool possesses a Server-Side Request Forgery (SSRF) vulnerability that could allow malicious actors to send crafted requests from the server to internal resources, potentially leaking sensitive information or causing unauthorized actions. This flaw affects versions from n/a through 1.3, posing a significant security risk to users who rely on this tool for affiliate marketing integration.

Affected Version(s)

Skimlinks Affiliate Marketing Tool <= 1.3

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.