Cross-site Scripting Vulnerability in My Auctions Allegro by Wphocus
CVE-2025-68566

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 December 2025

What is CVE-2025-68566?

The My Auctions Allegro plugin by Wphocus is susceptible to a Stored Cross-site Scripting (XSS) vulnerability due to inadequate input neutralization during webpage generation. This flaw allows attackers to inject malicious scripts that can be executed in the context of a user’s browser, potentially compromising user data and site integrity. The issue affects versions up to and including 3.6.32, urging users to implement security measures to mitigate potential attacks.

Affected Version(s)

My auctions allegro <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Nur Ibnu Hubab | Patchstack Bug Bounty Program
.
CVE-2025-68566 : Cross-site Scripting Vulnerability in My Auctions Allegro by Wphocus