Vulnerabilities and security researches for wp-auctions
Direction: ascendingDec 08, 2024
WordPress Auction Plugin # CVE-2024-54207
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 06, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Owen Cutajar & Hyder Jaffari WordPress Auction Plugin allows Stored XSS.This issue affects WordPress Auction Plugin: from n/a through 3.7.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
WordPress Auction Plugin # CVE-2024-51615
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 06, 2024
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Owen Cutajar & Hyder Jaffari WordPress Auction Plugin allows SQL Injection.This issue affects WordPress Auction Plugin: from n/a through 3.7.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jan 09, 2025
WordPress Auction Plugin # CVE-2025-22349
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 07, 2025
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Owen Cutajar & Hyder Jaffari WordPress Auction Plugin allows SQL Injection.This issue affects WordPress Auction Plugin: from n/a through 3.7.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jan 22, 2025
WordPress Auction Plugin # CVE-2024-8857
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 07, 2025
- Research Description
- The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Stored Cross-Site Scripting attacks.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
WordPress Auction Plugin # CVE-2024-8855
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 07, 2025
- Research Description
- The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL injection attacks
- Affected versions
-
Min -, max -.
- Status
-
vulnerable