SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2025-15485

HIGH · CVSS 8.2 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Auto x LINE WordPress plugin versions up to 1.0.0 lack proper authorization checks on certain REST endpoints, enabling unauthenticated users to modify plugin settings and clear logs. This vulnerability poses a significant risk as it can lead to unauthorized changes and potential exploitation of the WordPress site. WordPress administrators using this plugin should prioritize immediate updates to mitigate this high-severity threat.

CVE
CVE-2025-15485
Severity
HIGH
CVSS
8.2
EPSS
0.20%
WordPress

Original NVD Description

The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc