Cross-Site Request Forgery Vulnerability in My Auctions Allegro Plugin by WordPress
CVE-2025-68567

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 December 2025

What is CVE-2025-68567?

The My Auctions Allegro Free Edition plugin for WordPress has a vulnerability that allows attackers to exploit Cross-Site Request Forgery (CSRF) weaknesses. This flaw enables an unauthorized user to submit requests on behalf of authenticated users without their consent, potentially leading to unintended actions within the application. Affected versions range from n/a to 3.6.32.

Affected Version(s)

My auctions allegro <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Nur Ibnu Hubab | Patchstack Bug Bounty Program
.
CVE-2025-68567 : Cross-Site Request Forgery Vulnerability in My Auctions Allegro Plugin by WordPress