
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68567 is a Cross-Site Request Forgery (CSRF) vulnerability in the My Auctions Allegro WordPress plugin developed by wphocus. It affects all versions of the my-auctions-allegro-free-edition plugin through version 3.6.33 (some sources cite 3.6.32 as the upper bound). The vulnerability was published on December 24, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.4 (Medium) (Red Hat CVE, Patchstack).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to properly validate or enforce anti-CSRF tokens on sensitive state-changing requests. An unauthenticated attacker can craft a malicious web page or link that, when visited by an authenticated WordPress administrator or user, silently submits forged requests to the plugin's endpoints on their behalf. Exploitation requires no special privileges from the attacker but does require user interaction — specifically, a logged-in victim must be tricked into visiting a malicious URL or page. No complex preconditions beyond a standard WordPress installation running the vulnerable plugin version are needed (Red Hat CVE, Patchstack).
Successful exploitation allows an attacker to perform unauthorized actions on behalf of an authenticated user without their knowledge or consent. Potential consequences include modifying plugin settings, deleting auction content, changing user permissions, or otherwise manipulating the WordPress site's configuration. The integrity and availability impacts are rated low individually, but chained with social engineering, the vulnerability could contribute to broader site compromise (Red Hat CVE).
There is currently no public proof-of-concept exploit code and no evidence of in-the-wild exploitation for CVE-2025-68567. The EPSS score is approximately 0.018%, indicating a very low probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been reported for this vulnerability (Red Hat CVE, Patchstack).
wp-admin/admin-post.php or wp-admin/admin-ajax.php with plugin-specific action parameters) from unusual referrer origins or with no referrer header.Referer header, which may indicate a CSRF attempt from a third-party page.Administrators should immediately update the My Auctions Allegro plugin to the latest version available beyond 3.6.33, which includes a patch for this CSRF vulnerability. As a temporary workaround, restrict access to the WordPress admin panel to trusted IP addresses and educate users about the risks of clicking unknown links while authenticated. Additionally, deploying a WordPress security plugin that enforces CSRF protections or a Web Application Firewall (WAF) can provide supplementary defense (Patchstack, Red Hat CVE).
The vulnerability received brief social media coverage shortly after disclosure, with mentions on Mastodon and Bluesky via TheHackerWire. No significant vendor statements, in-depth researcher commentary, or major media coverage has been identified beyond the initial Patchstack advisory and automated vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."