PT-2025-9650 · WordPress · The Ultimate Wordpress Auction Plugin

Brian Sans-Souci

+1

·

Published

2025-03-04

·

Updated

2025-03-05

·

CVE-2025-0958

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions The Ultimate WordPress Auction Plugin versions prior to 4.3.0
Description The issue allows authenticated attackers with Contributor-level access and above to access functionality unauthorized, enabling them to delete arbitrary auctions, posts, and pages, and execute other actions related to auction handling.
Recommendations For versions prior to 4.3.0, update to version 4.3.0 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-0958

Affected Products

The Ultimate Wordpress Auction Plugin