CVE-2025-15485

high

Description

The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc

References

https://wpscan.com/vulnerability/3e9da619-bce1-49b5-aa35-dce22b72f9e6/

Details

Source: Mitre, NVD

Published: 2026-09-02

Updated: 2026-09-03

Risk Information

CVSS v2

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:P/A:N

Severity: High

CVSS v3

Base Score: 8.2

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Severity: High

EPSS

EPSS: 0.00204