Cross-Site Request Forgery Vulnerability in Auto SEO by Phillip.Gooch
CVE-2025-25147

7.1HIGH

Key Information:

Vendor
Phillip.gooch
Status
Auto Seo
Vendor
CVE Published:
7 February 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Auto SEO plugin developed by Phillip.Gooch, which can lead to stored Cross-Site Scripting (XSS) attacks. This vulnerability affects versions from n/a to 2.5.6, putting users at risk. An attacker can exploit this weakness by tricking a user into executing unintended actions on their site, potentially compromising sensitive data or injecting malicious scripts. Website administrators are urged to update to the latest versions and implement security best practices to mitigate risks.

Affected Version(s)

Auto SEO <= 2.5.6

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdi Pranata (Patchstack Alliance)
.