Medium 5.4 Unfixed
2025-12-16≤ 4.3.3
CVE-2025-68084
Minimum safe version
4.3.0
Update to 4.3.0 or later to address 9 fixable vulnerabilities
CVE-2025-68084
CVE-2025-66125
WordPress Ultimate Auction Plugin <= 4.2.9 is vulnerable to Arbitrary Content Deletion
WordPress Ultimate Auction Plugin <= 4.2.6 is vulnerable to Broken Access Control
CVE-2024-37543
Ultimate WordPress Auction Plugin < 1.0.1 - Cross-Site Request Forgery
Ultimate Auction <= 4.0.5 - Cross-Site Request Forgery and Cross-Site Scripting
Ultimate Auction 1.0 - Cross-Site Request Forgery (CSRF)
Ultimate Auction < 4.0.6 - Multiple CSRF & XSS
WordPress Ultimate Auction Plugin 1.0 - CSRF
WordPress Ultimate Auction plugin <= 4.0.5 - Multiple CSRF & XSS vulnerabilities