CVE-2025-0958 Information

Description

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to and including 4.2.9. This makes it possible for authenticated attackers with Contributor-level access and above to delete arbitrary auctions posts as well as pages and allows them to execute other actions related to auction handling.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Reference

https://plugins.trac.wordpress.org/browser/ultimate-auction/trunk/ajax-actions/send-private-msg.php#L35 https://plugins.trac.wordpress.org/browser/ultimate-auction/trunk/ultimate-auction.php#L219 https://plugins.trac.wordpress.org/browser/ultimate-auction/trunk/ultimate-auction.php#L274 https://plugins.trac.wordpress.org/changeset/3242416/ultimate-auction/trunk/ultimate-auction.php https://www.wordfence.com/threat-intel/vulnerabilities/id/af3675c9-3a6b-4139-85e8-2fc57f290e82?source=cve

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

LOW

Base Severity

6.3

Share on: