Access Control Flaw in WP AutoKeyword by EXEIdeas International
CVE-2025-28997
5.3MEDIUM
What is CVE-2025-28997?
A missing authorization vulnerability has been identified in the WP AutoKeyword plugin developed by EXEIdeas International. This flaw allows attackers to exploit incorrectly configured access control security levels, potentially leading to unauthorized access to sensitive functionalities. The affected versions of WP AutoKeyword make it easier for malicious actors to gain elevated privileges, emphasizing the need for stringent access control measures.
Affected Version(s)
WP AutoKeyword <= 1.0