The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc
Metrics
Affected Vendors & Products
References
History
Wed, 02 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc | |
| Title | Auto x LINE <= 1.0.0 – Unauthenticated REST API Endpoints Call | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-09-02T14:25:47.794Z
Updated: 2026-09-02T14:57:36.153Z
Reserved: 2026-01-07T22:25:25.440Z
Link: CVE-2025-15485
Updated: 2026-09-02T14:43:13.965Z
Status : Deferred
Published: 2026-09-02T15:17:36.450
Modified: 2026-09-03T17:50:37.690
Link: CVE-2025-15485
No data.