Auto SEO
Auto SEO has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Auto SEO has a vendor fix available, so running the current release closes it.
All of these findings were reported by Abdi Pranata. Auto SEO is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-25147Auto SEO <= 2.5.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Auto SEO
Author
Phillip.Gooch
Auto SEO is a simple way to add all your SEO header tags from a single interface. It will generate new meta tags, replacing any old ones your theme may add already, that are fully customized to target the audience you want. Don’t want to override everything? No problem, you choose what to override and on what post types to do it. Take the tedium out of SEO. Note: because Auto SEO is designed to override existing meta tags when needed it works a bit differently than other SEO plugins and as such may not work on every theme. While it has been tested with a wide variety of different themes naturally it would be impossible to test them all. If your having trouble getting it to active on your site I’m more than willing to help, just let me know what theme your using and I’ll take a look, contact information inside the plugin.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C