Cross-Site Request Forgery Vulnerability in Auto Tag Links Plugin by SEO Roma
CVE-2025-27335

4.3MEDIUM

Key Information:

Vendor
Free Plug In By Seo Roma
Status
Auto Tag Links
Vendor
CVE Published:
24 February 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Auto Tag Links plugin developed by SEO Roma, which can allow attackers to induce users to perform unintended actions on web applications. The flaw affects all versions from n/a up to 1.0.13 and poses a risk for users who utilize this plugin, enabling potential exploitation without user consent. Swift remediation is necessary to protect users from unauthorized manipulation.

Affected Version(s)

Auto Tag Links <= 1.0.13

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.