Description
Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Stored XSS.This issue affects My auctions allegro: from n/a through <= 3.6.33.
Published: 2025-04-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery (CSRF) flaw in the My auctions allegro plugin enables an attacker to trigger an action on behalf of a privileged user, leading to the injection of malicious script that is stored on the site. The vulnerability allows the crafted request to bypass normal authentication checks and embed code that will execute whenever the affected content is viewed, compromising the integrity and confidentiality of the site’s content and potentially allowing data exfiltration or defacement. The core weakness is a failure to validate CSRF tokens and enforce proper input handling, as reflected by CWE‑352.

Affected Systems

The issue affects the free edition of the My auctions allegro plugin distributed by wphocus. All pre‑3.6.34 releases—including 3.6.33—are susceptible. End users running this plugin on any WordPress site should verify the installed version and consider it compromised until addressed.

Risk and Exploitability

The reported CVSS score of 7.1 indicates a high‑severity vulnerability, while an EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly known active exploitation is confirmed. An attacker would need to entice a logged‑in user or exploit existing privileges to send the forged request, typically via a malicious link or embedded form. Once exploited, stored XSS can impact all users who view the compromised content.

Generated by OpenCVE AI on May 1, 2026 at 10:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the My auctions allegro plugin to the latest version (≥3.6.34).
  • If an upgrade is not immediately possible, disable or delete the plugin until the patch is applied.
  • Configure the WordPress site to enforce CSRF tokens on all privileged actions and validate input coming from the plugin.
  • Apply site‑wide content security policy (CSP) headers to mitigate the impact of any residual cross‑site scripting.

Generated by OpenCVE AI on May 1, 2026 at 10:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10878 Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro allows Stored XSS.This issue affects My auctions allegro: from n/a through 3.6.20.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro allows Stored XSS.This issue affects My auctions allegro: from n/a through 3.6.20. Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Stored XSS.This issue affects My auctions allegro: from n/a through <= 3.6.33.
Title WordPress My auctions allegro plugin <= 3.6.20 - Cross Site Request Forgery (CSRF) vulnerability WordPress My auctions allegro plugin <= 3.6.33 - Cross Site Request Forgery (CSRF) vulnerability
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 14 Apr 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Apr 2025 11:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro allows Stored XSS.This issue affects My auctions allegro: from n/a through 3.6.20.
Title WordPress My auctions allegro plugin <= 3.6.20 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:46.647Z

Reserved: 2025-02-17T11:52:15.089Z

Link: CVE-2025-27009

cve-icon Vulnrichment

Updated: 2025-04-14T11:51:06.975Z

cve-icon NVD

Status : Deferred

Published: 2025-04-14T11:15:15.137

Modified: 2026-06-17T09:02:45.243

Link: CVE-2025-27009

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T10:30:15Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)