Description
Cross-Site Request Forgery (CSRF) vulnerability in Phillip.Gooch Auto SEO auto-seo allows Stored XSS.This issue affects Auto SEO: from n/a through <= 2.5.6.
Published: 2025-02-07
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Phillip.Gooch Auto SEO for WordPress contains a cross‑site request forgery flaw that allows an attacker to inject malicious script into stored configuration data. The injected script is then rendered when an administrator or any user with access views the affected page, enabling client‑side code execution in the victim’s browser. This can result in credential theft, session hijacking, defacement, or further lateral movement within the site’s administrative interface.

Affected Systems

The vulnerability exists in Auto SEO versions up to and including 2.5.6. All installations of the plugin from earlier unspecified releases through 2.5.6 are potentially impacted, regardless of the WordPress core version. No specific hardware or operating system requirements are noted, and the attack targets the WordPress admin area rather than the underlying server environment.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity level, while the EPSS score of less than 1% suggests a low current likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to be authenticated with sufficient privileges to submit a crafted CSRF request; the attacker must generate a request that the victim’s browser will submit, relying on the victim’s session cookie. Once the input is stored, any subsequent page rendering by an authorized user executes the injected script.

Generated by OpenCVE AI on May 1, 2026 at 16:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Auto SEO plugin to the latest released version that removes the CSRF flaw.
  • Verify that the plugin’s forms employ anti‑CSRF tokens to prevent unauthorized state changes.
  • Restrict administrative access to trusted users only and apply the principle of least privilege, ensuring that users lacking rights to modify plugin settings cannot be targeted.

Generated by OpenCVE AI on May 1, 2026 at 16:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4057 Cross-Site Request Forgery (CSRF) vulnerability in Phillip.Gooch Auto SEO allows Stored XSS. This issue affects Auto SEO: from n/a through 2.5.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Phillip.Gooch Auto SEO allows Stored XSS. This issue affects Auto SEO: from n/a through 2.5.6. Cross-Site Request Forgery (CSRF) vulnerability in Phillip.Gooch Auto SEO auto-seo allows Stored XSS.This issue affects Auto SEO: from n/a through <= 2.5.6.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Feb 2025 10:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Phillip.Gooch Auto SEO allows Stored XSS. This issue affects Auto SEO: from n/a through 2.5.6.
Title WordPress Auto SEO plugin <= 2.5.6 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:36.997Z

Reserved: 2025-02-03T13:35:08.294Z

Link: CVE-2025-25147

cve-icon Vulnrichment

Updated: 2025-02-12T20:44:34.221Z

cve-icon NVD

Status : Deferred

Published: 2025-02-07T10:15:20.063

Modified: 2026-06-17T09:00:22.550

Link: CVE-2025-25147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T17:00:11Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)