Cross-Site Request Forgery Vulnerability in David Merinas Auto Last Youtube Video Plugin
CVE-2025-58843
7.1HIGH
What is CVE-2025-58843?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Auto Last Youtube Video plugin developed by David Merinas. This security flaw allows attackers to execute unauthorized actions on behalf of an authenticated user, potentially leading to Stored Cross-Site Scripting (XSS) attacks. The vulnerability affects versions from n/a through 1.0.7, making it critical for users of this plugin to ensure they are updated or to apply necessary mitigations.
Affected Version(s)
Auto Last Youtube Video <= 1.0.7