PT-2026-4026 · WordPress · Wphocus My Auctions Allegro

Published

2026-01-22

·

Updated

2026-01-25

·

CVE-2025-67943

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions wphocus My auctions allegro versions through 3.6.32
Description The software contains a flaw related to improper input handling during web page creation, which can lead to Reflected Cross-site Scripting (XSS). This allows for the injection of malicious scripts into web pages viewed by users.
Recommendations Versions prior to 3.6.32 should be updated.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-67943

Affected Products

Wphocus My Auctions Allegro