auctionplugin records
2 published records for vendor auctionplugin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2025-4204No exploit | Ultimate Auction Pro <= 1.5.2 - Unauthenticated SQL Injection via 'auction_id'auctionplugin · ultimate wordpress auction plugin · CWE-89 | High7.5 | — | 0.4% | May 2, 2025 |
25Monitor | CVE-2025-0958No exploit | Ultimate WordPress Auction Plugin <= 4.2.9 - Missing Authorization to Arbitrary Post Deletionauctionplugin · ultimate auction · CWE-20 | Medium6.3 | — | 0.4% | Mar 4, 2025 |
- CVE-2025-420430Monitor
Ultimate Auction Pro <= 1.5.2 - Unauthenticated SQL Injection via 'auction_id'
HighCVSS 7.5No exploitEPSS 0%auctionplugin · ultimate wordpress auction pluginMay 2, 2025
- CVE-2025-095825Monitor
Ultimate WordPress Auction Plugin <= 4.2.9 - Missing Authorization to Arbitrary Post Deletion
MediumCVSS 6.3No exploitEPSS 0%auctionplugin · ultimate auctionMar 4, 2025