« Back to list

Wpmarka

Wpmarka Wordpress Auction: vulnerabilities and CVEs

Wpmarka Wordpress Auction has 2 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months0
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-8857Medium (4.8)0.32%—Jan 7, 2025
The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Stored Cross-Site Scripting attacks.
CVE-2024-8855Critical (9.8)0.63%—Jan 7, 2025
The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL injection attacks

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Wpmarka