Executive brief
The Ultimate WooCommerce Auction Pro plugin for WordPress, which adds auction functionality to e-commerce sites, is vulnerable to a security flaw that allows attackers to execute malicious scripts in a user's browser. This occurs when a user clicks a specially crafted link, potentially allowing an attacker to hijack the session of a high-privileged user like an administrator. Such an attack could lead to unauthorized changes to the website or theft of sensitive administrative data.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Ultimate WooCommerce Auction Pro plugin for WordPress (up to and including version 2.4.5). The vulnerability is located in the 'uwa_auctions_bids_list' parameter, which is not properly sanitized or escaped before being rendered back in the web page. An unauthenticated remote attacker can exploit this by tricking a user, particularly one with administrative privileges, into clicking a malicious link. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session. As of the advisory date, no official fix has been released.
Affected products
- Unknown Ultimate WooCommerce Auction Pro <= 2.4.5
Timeline
- 2026-06-01: disclosed: Publicly published by WPScan
- 2026-06-22: advisory: CVE published to NVD dataset