CVE-2024-12252: Seobeginner Seo Lat Auto Post
Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.
The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remote_update AJAX action in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to overwrite the seo-beginner-auto-post.php file which can be leveraged to achieve remote code execution.
Affected products
- Seobeginner Seo Lat Auto Post: up to and including 2.2.1
Published 2025-01-07. Last modified 2026-06-17.