CVE-2025-6247
Last modified
CVE-2025-6247 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.118.0. This is due to missing or incorrect nonce validation on one of its functions. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.118.0. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to update campaigns and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-6247?
How severe is CVE-2025-6247?
How do I fix CVE-2025-6247?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-62464Buffer over-read in Windows Projected File System allows an …7.8
- CVE-2025-62465Null pointer dereference in Windows DirectX allows an author…6.5
- CVE-2025-62466Null pointer dereference in Windows Client-Side Caching (CSC…7.8
- CVE-2025-62467Integer overflow or wraparound in Windows Projected File Sys…7.8
- CVE-2025-62468Out-of-bounds read in Windows Defender Firewall Service allo…5.5
- CVE-2025-62469Concurrent execution using shared resource with improper syn…7
- CVE-2025-62470Heap-based buffer overflow in Windows Common Log File System…7.8
- CVE-2025-62472Use of uninitialized resource in Windows Remote Access Conne…7.8
- CVE-2025-62473Buffer over-read in Windows Routing and Remote Access Servic…6.5
- CVE-2025-62474Improper access control in Windows Remote Access Connection …7.8
- CVE-2025-62475Vulnerability in the Oracle ZFS Storage Appliance Kit produc…4.9
- CVE-2025-62476Vulnerability in the Oracle ZFS Storage Appliance Kit produc…4.9
Are you affected by CVE-2025-6247?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
