CVE-2015-9425: Byonepress Social Locker
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opanda-item&page=license-manager-sociallocker-next licensekey parameter.
Affected products
- Byonepress Social Locker: before 4.2.5 (fixed in 4.2.5)
Published 2019-09-26. Last modified 2026-06-17.