Cross-Site Request Forgery Vulnerability in Auto SEO by Phillip.Gooch
CVE-2025-25147
What is CVE-2025-25147?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Auto SEO plugin developed by Phillip.Gooch, which can lead to stored Cross-Site Scripting (XSS) attacks. This vulnerability affects versions from n/a to 2.5.6, putting users at risk. An attacker can exploit this weakness by tricking a user into executing unintended actions on their site, potentially compromising sensitive data or injecting malicious scripts. Website administrators are urged to update to the latest versions and implement security best practices to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Auto SEO <= 2.5.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved