Cross-Site Request Forgery Vulnerability in Auto SEO by Phillip.Gooch
CVE-2025-25147
7.1HIGH
Key Information:
- Vendor
- Phillip.gooch
- Status
- Auto Seo
- Vendor
- CVE Published:
- 7 February 2025
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Auto SEO plugin developed by Phillip.Gooch, which can lead to stored Cross-Site Scripting (XSS) attacks. This vulnerability affects versions from n/a to 2.5.6, putting users at risk. An attacker can exploit this weakness by tricking a user into executing unintended actions on their site, potentially compromising sensitive data or injecting malicious scripts. Website administrators are urged to update to the latest versions and implement security best practices to mitigate risks.
Affected Version(s)
Auto SEO <= 2.5.6
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdi Pranata (Patchstack Alliance)