PT-2025-49230 · WordPress · My Auctions Allegro Plugin

Published

2025-12-05

·

Updated

2025-12-10

·

CVE-2025-12850

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions My auctions allegro plugin for WordPress versions through 3.6.32
Description The My auctions allegro plugin for WordPress is susceptible to SQL Injection via the auction id parameter. Insufficient escaping of user-supplied input and a lack of proper SQL query preparation allow unauthenticated attackers to inject additional SQL queries into existing queries. This can lead to the extraction of sensitive information from the database.
Recommendations Versions prior to 3.6.32 should be updated to address this issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-12850

Affected Products

My Auctions Allegro Plugin