First published: Fri Feb 07 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in djjmz Simple Auto Tag allows Stored XSS. This issue affects Simple Auto Tag: from n/a through 1.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Simple Auto Tag | <=1.1 | |
djjmz Simple Auto Tag | <=1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25153 is considered a high-severity Cross-Site Request Forgery (CSRF) vulnerability that leads to stored XSS attacks in the Simple Auto Tag plugin.
To fix CVE-2025-25153, update the Simple Auto Tag plugin to a version above 1.1 to mitigate the vulnerability.
CVE-2025-25153 affects Simple Auto Tag versions up to and including 1.1.
CVE-2025-25153 is a Cross-Site Request Forgery (CSRF) vulnerability that also allows stored XSS.
As of now, there are no publicly disclosed exploits specifically for CVE-2025-25153, but it is advisable to take preventive action.