CVE-2025-15485EPSS p9.4%
CVE-2025-15485CVE-2025-15485
Description
The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc
Scoring
| CVSS | 8.2 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
| EPSS | 0.20% probability of exploitation · percentile 9.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-03 |