CVE-2025-15485 PUBLISHED

Auto x LINE <= 1.0.0 – Unauthenticated REST API Endpoints Call

Assigner: WPScan
Reserved: 07.01.2026 Published: 02.09.2026 Updated: 02.09.2026

The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS Score: 8.2

Product Status

Vendor Unknown
Product Auto x LINE
Versions Default: unknown
  • affected from 0 to 1.0.0 (incl.)

Credits

  • Khaled Alenazi (Nxploited) finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE