Executive brief
The Ultimate WooCommerce Auction Pro plugin for WordPress, which adds auction functionality to e-commerce sites, is vulnerable to a security flaw. An attacker can trick an administrator into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the admin's browser. This could lead to the theft of sensitive session information or unauthorized changes to the website's configuration.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Ultimate WooCommerce Auction Pro plugin for WordPress (up to and including version 2.4.5). The vulnerability is located in the 'uwa_manage_auctions' parameter, which is not properly sanitized or escaped before being rendered back to the user. An unauthenticated remote attacker can exploit this by crafting a malicious URL and tricking a high-privileged user, such as an administrator, into visiting it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or administrative actions performed on behalf of the victim. As of the advisory date, no official fix has been confirmed.
Affected products
- Unknown Ultimate WooCommerce Auction Pro <= 2.4.5
Timeline
- 2026-06-01: disclosed: Publicly published via WPScan
- 2026-06-22: advisory: NVD publication date