CVE-2025-15485

The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc

  • Published Sep 2, 2026
  • CVSS 8.2 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2025-15485 at the National Vulnerability Database