PT-2026-4026 · WordPress · Wphocus My Auctions Allegro

CVE-2025-67943

·

Published

2026-01-22

·

Updated

2026-01-25

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions wphocus My auctions allegro versions through 3.6.32
Description The software contains a flaw related to improper input handling during web page creation, which can lead to Reflected Cross-site Scripting (XSS). This allows for the injection of malicious scripts into web pages viewed by users.
Recommendations Versions prior to 3.6.32 should be updated.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67943

Affected Products

Wphocus My Auctions Allegro