My auctions allegro <= 3.6.34 - Reflected Cross-Site Scripting
medium
The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.6.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...
- CVSS:
- 6.1
- Affected:
- up to 3.6.34
- Fix:
- No patched version reported
- Disclosed:
- Mar 5, 2026
CVE-2026-22491 on NVD →
My auctions allegro [my-auctions-allegro-free-edition] <= 3.6.33 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows PHP Local File Inclusion.This issue affects My auctions allegro: from n/a through <= 3.6.33.
- Affected:
- up to 3.6.33
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2026-22464 on NVD →
My auctions allegro [my-auctions-allegro-free-edition] <= 3.6.32 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Reflected XSS.This issue affects My auctions allegro: from n/a through <= 3.6.32.
- Affected:
- up to 3.6.32
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-67943 on NVD →
My auctions allegro <= 3.6.32 - Unauthenticated Stored Cross-Site Scripting
high
The My auctions allegro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.32 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user a...
- CVSS:
- 7.2
- Affected:
- up to 3.6.32
- Fixed in:
- 3.6.33
- Disclosed:
- Jan 19, 2026
CVE-2025-67943 on NVD →
My auctions allegro <= 3.6.33 - Authenticated (Contributor+) Local File Inclusion
high
The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.6.33. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those...
- CVSS:
- 7.5
- Affected:
- up to 3.6.33
- Fixed in:
- 3.6.34
- Disclosed:
- Jan 4, 2026
CVE-2026-22464 on NVD →
My auctions allegro [my-auctions-allegro-free-edition] <= 3.6.32 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Stored XSS.This issue affects My auctions allegro: from n/a through <= 3.6.32.
- Affected:
- up to 3.6.32
- Fix:
- No patched version reported
- Disclosed:
- Dec 24, 2025
CVE-2025-68566 on NVD →
My auctions allegro [my-auctions-allegro-free-edition] <= 3.6.32 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Cross Site Request Forgery.This issue affects My auctions allegro: from n/a through <= 3.6.32.
- Affected:
- up to 3.6.32
- Fix:
- No patched version reported
- Disclosed:
- Dec 24, 2025
CVE-2025-68567 on NVD →
My auctions allegro <= 3.6.33 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The My auctions allegro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in...
- CVSS:
- 4.4
- Affected:
- up to 3.6.33
- Fix:
- No patched version reported
- Disclosed:
- Dec 17, 2025
CVE-2025-68566 on NVD →
My auctions allegro <= 3.6.33 - Cross-Site Request Forgery
medium
The My auctions allegro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.33. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they...
- CVSS:
- 4.3
- Affected:
- up to 3.6.33
- Fixed in:
- 3.6.34
- Disclosed:
- Dec 17, 2025
CVE-2025-68567 on NVD →
My auctions allegro [my-auctions-allegro-free-edition] < 3.6.33
unknown
[en] The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.32 via the 'controller' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those...
- Affected:
- up to 3.6.33
- Fixed in:
- 3.6.33
- Disclosed:
- Dec 5, 2025
CVE-2025-12851 on NVD →
My auctions allegro [my-auctions-allegro-free-edition] < 3.6.33
unknown
[en] The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 3.6.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticat...
- Affected:
- up to 3.6.33
- Fixed in:
- 3.6.33
- Disclosed:
- Dec 5, 2025
CVE-2025-12850 on NVD →
My auctions allegro <= 3.6.32 - Unauthenticated Local File Inclusion via controller
high
The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.32 via the 'controller' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files...
- CVSS:
- 8.1
- Affected:
- up to 3.6.32
- Fixed in:
- 3.6.33
- Disclosed:
- Dec 4, 2025
CVE-2025-12851 on NVD →
My auctions allegro <= 3.6.32 - Unauthenticated SQL Injection via auction_id
high
The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 3.6.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated at...
- CVSS:
- 7.5
- Affected:
- up to 3.6.32
- Fixed in:
- 3.6.33
- Disclosed:
- Dec 4, 2025
CVE-2025-12850 on NVD →
My auctions allegro [my-auctions-allegro-free-edition] < 3.6.32
unknown
[en] The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 3.6.31 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...
- Affected:
- up to 3.6.32
- Fixed in:
- 3.6.32
- Disclosed:
- Oct 11, 2025
CVE-2025-10048 on NVD →
My Auctions Allegro Plugin <= 3.6.31 - Authenticated (Admin+) SQL Injection
medium
The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 3.6.31 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers...
- CVSS:
- 4.9
- Affected:
- up to 3.6.31
- Fixed in:
- 3.6.32
- Disclosed:
- Oct 10, 2025
CVE-2025-10048 on NVD →
My auctions allegro <= 3.6.33 - Cross-Site Request Forgery
medium
The My auctions allegro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.33. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site...
- CVSS:
- 4.3
- Affected:
- up to 3.6.33
- Fixed in:
- 3.6.34
- Disclosed:
- Apr 14, 2025
CVE-2025-27009 on NVD →
My auctions allegro [my-auctions-allegro-free-edition] <= 3.6.26 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro allows Stored XSS.This issue affects My auctions allegro: from n/a through 3.6.20.
- Affected:
- up to 3.6.26
- Fix:
- No patched version reported
- Disclosed:
- Apr 14, 2025
CVE-2025-27009 on NVD →
My auctions allegro <= 3.6.20 - Authenticated (Contributor+) SQL Injection
medium
The My auctions allegro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level acces...
- CVSS:
- 6.5
- Affected:
- up to 3.6.20
- Fixed in:
- 3.6.21
- Disclosed:
- Mar 31, 2025
CVE-2025-31542 on NVD →
My auctions allegro [my-auctions-allegro-free-edition] <= 3.6.25 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wphocus My auctions allegro allows Blind SQL Injection. This issue affects My auctions allegro: from n/a through 3.6.20.
- Affected:
- up to 3.6.25
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2025
CVE-2025-31542 on NVD →
My auctions allegro [my-auctions-allegro-free-edition] < 3.6.19
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPHocus My auctions allegro allows Reflected XSS. This issue affects My auctions allegro: from n/a through 3.6.18.
- Affected:
- up to 3.6.19
- Fixed in:
- 3.6.19
- Disclosed:
- Jan 21, 2025
CVE-2025-22733 on NVD →
My auctions allegro <= 3.6.18 - Reflected Cross-Site Scripting
medium
The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.6.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...
- CVSS:
- 6.1
- Affected:
- up to 3.6.18
- Fixed in:
- 3.6.19
- Disclosed:
- Jan 15, 2025
CVE-2025-22733 on NVD →
My auctions allegro [my-auctions-allegro-free-edition] < 3.6.18
unknown
[en] The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 3.6.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- Affected:
- up to 3.6.18
- Fixed in:
- 3.6.18
- Disclosed:
- Dec 3, 2024
CVE-2024-11707 on NVD →
My auctions allegro <= 3.6.17 - Reflected Cross-Site Scripting
medium
The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 3.6.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.1
- Affected:
- up to 3.6.17
- Fixed in:
- 3.6.18
- Disclosed:
- Dec 2, 2024
CVE-2024-11707 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database