plugin

My Auctions Allegro Free Edition Vulnerabilities

23 known security issues reported for the My Auctions Allegro Free Edition WordPress plugin. Most recent disclosed Mar 5, 2026.

4 high 8 medium

Running My Auctions Allegro Free Edition on your site? Check whether your installed version is affected.

Scan your site free

My auctions allegro <= 3.6.34 - Reflected Cross-Site Scripting

medium

The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.6.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...

CVSS:
6.1
Affected:
up to 3.6.34
Fix:
No patched version reported
Disclosed:
Mar 5, 2026

CVE-2026-22491 on NVD →

My auctions allegro [my-auctions-allegro-free-edition] <= 3.6.33 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows PHP Local File Inclusion.This issue affects My auctions allegro: from n/a through <= 3.6.33.

Affected:
up to 3.6.33
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2026-22464 on NVD →

My auctions allegro [my-auctions-allegro-free-edition] <= 3.6.32 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Reflected XSS.This issue affects My auctions allegro: from n/a through <= 3.6.32.

Affected:
up to 3.6.32
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-67943 on NVD →

My auctions allegro <= 3.6.32 - Unauthenticated Stored Cross-Site Scripting

high

The My auctions allegro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.32 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user a...

CVSS:
7.2
Affected:
up to 3.6.32
Fixed in:
3.6.33
Disclosed:
Jan 19, 2026

CVE-2025-67943 on NVD →

My auctions allegro <= 3.6.33 - Authenticated (Contributor+) Local File Inclusion

high

The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.6.33. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those...

CVSS:
7.5
Affected:
up to 3.6.33
Fixed in:
3.6.34
Disclosed:
Jan 4, 2026

CVE-2026-22464 on NVD →

My auctions allegro [my-auctions-allegro-free-edition] <= 3.6.32 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Stored XSS.This issue affects My auctions allegro: from n/a through <= 3.6.32.

Affected:
up to 3.6.32
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68566 on NVD →

My auctions allegro [my-auctions-allegro-free-edition] <= 3.6.32 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Cross Site Request Forgery.This issue affects My auctions allegro: from n/a through <= 3.6.32.

Affected:
up to 3.6.32
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68567 on NVD →

My auctions allegro <= 3.6.33 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The My auctions allegro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in...

CVSS:
4.4
Affected:
up to 3.6.33
Fix:
No patched version reported
Disclosed:
Dec 17, 2025

CVE-2025-68566 on NVD →

My auctions allegro <= 3.6.33 - Cross-Site Request Forgery

medium

The My auctions allegro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.33. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they...

CVSS:
4.3
Affected:
up to 3.6.33
Fixed in:
3.6.34
Disclosed:
Dec 17, 2025

CVE-2025-68567 on NVD →

My auctions allegro [my-auctions-allegro-free-edition] < 3.6.33

unknown

[en] The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.32 via the 'controller' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those...

Affected:
up to 3.6.33
Fixed in:
3.6.33
Disclosed:
Dec 5, 2025

CVE-2025-12851 on NVD →

My auctions allegro [my-auctions-allegro-free-edition] < 3.6.33

unknown

[en] The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 3.6.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticat...

Affected:
up to 3.6.33
Fixed in:
3.6.33
Disclosed:
Dec 5, 2025

CVE-2025-12850 on NVD →

My auctions allegro <= 3.6.32 - Unauthenticated Local File Inclusion via controller

high

The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.32 via the 'controller' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files...

CVSS:
8.1
Affected:
up to 3.6.32
Fixed in:
3.6.33
Disclosed:
Dec 4, 2025

CVE-2025-12851 on NVD →

My auctions allegro <= 3.6.32 - Unauthenticated SQL Injection via auction_id

high

The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 3.6.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated at...

CVSS:
7.5
Affected:
up to 3.6.32
Fixed in:
3.6.33
Disclosed:
Dec 4, 2025

CVE-2025-12850 on NVD →

My auctions allegro [my-auctions-allegro-free-edition] < 3.6.32

unknown

[en] The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 3.6.31 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...

Affected:
up to 3.6.32
Fixed in:
3.6.32
Disclosed:
Oct 11, 2025

CVE-2025-10048 on NVD →

My Auctions Allegro Plugin <= 3.6.31 - Authenticated (Admin+) SQL Injection

medium

The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 3.6.31 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers...

CVSS:
4.9
Affected:
up to 3.6.31
Fixed in:
3.6.32
Disclosed:
Oct 10, 2025

CVE-2025-10048 on NVD →

My auctions allegro <= 3.6.33 - Cross-Site Request Forgery

medium

The My auctions allegro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.33. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site...

CVSS:
4.3
Affected:
up to 3.6.33
Fixed in:
3.6.34
Disclosed:
Apr 14, 2025

CVE-2025-27009 on NVD →

My auctions allegro [my-auctions-allegro-free-edition] <= 3.6.26 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro allows Stored XSS.This issue affects My auctions allegro: from n/a through 3.6.20.

Affected:
up to 3.6.26
Fix:
No patched version reported
Disclosed:
Apr 14, 2025

CVE-2025-27009 on NVD →

My auctions allegro <= 3.6.20 - Authenticated (Contributor+) SQL Injection

medium

The My auctions allegro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level acces...

CVSS:
6.5
Affected:
up to 3.6.20
Fixed in:
3.6.21
Disclosed:
Mar 31, 2025

CVE-2025-31542 on NVD →

My auctions allegro [my-auctions-allegro-free-edition] <= 3.6.25 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wphocus My auctions allegro allows Blind SQL Injection. This issue affects My auctions allegro: from n/a through 3.6.20.

Affected:
up to 3.6.25
Fix:
No patched version reported
Disclosed:
Mar 31, 2025

CVE-2025-31542 on NVD →

My auctions allegro [my-auctions-allegro-free-edition] < 3.6.19

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPHocus My auctions allegro allows Reflected XSS. This issue affects My auctions allegro: from n/a through 3.6.18.

Affected:
up to 3.6.19
Fixed in:
3.6.19
Disclosed:
Jan 21, 2025

CVE-2025-22733 on NVD →

My auctions allegro <= 3.6.18 - Reflected Cross-Site Scripting

medium

The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.6.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...

CVSS:
6.1
Affected:
up to 3.6.18
Fixed in:
3.6.19
Disclosed:
Jan 15, 2025

CVE-2025-22733 on NVD →

My auctions allegro [my-auctions-allegro-free-edition] < 3.6.18

unknown

[en] The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 3.6.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

Affected:
up to 3.6.18
Fixed in:
3.6.18
Disclosed:
Dec 3, 2024

CVE-2024-11707 on NVD →

My auctions allegro <= 3.6.17 - Reflected Cross-Site Scripting

medium

The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 3.6.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

CVSS:
6.1
Affected:
up to 3.6.17
Fixed in:
3.6.18
Disclosed:
Dec 2, 2024

CVE-2024-11707 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database