Auto x LINE <= 1.0.0 – Unauthenticated REST API Endpoints Call
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.2epss 0.2%
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Affected products
Unknown · Auto x LINEpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/3e9da619-bce1-49b5-aa35-dce22b72f9e6/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.