CVE-2025-15485: Unknown Auto X Line

High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.

The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc

Affected products

  • Unknown Auto X Line: up to and including 1.0.0

Published 2026-09-02. Last modified 2026-09-03.