CVE-2015-9425: Byonepress Social Locker

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opanda-item&page=license-manager-sociallocker-next licensekey parameter.

Affected products

  • Byonepress Social Locker: before 4.2.5 (fixed in 4.2.5)

Published 2019-09-26. Last modified 2026-06-17.