Wpmarka's vulnerability footprint centers on WordPress Auction, a plugin extending WordPress with auction functionality, where disclosed issues cluster around input-handling flaws in web contexts. The durable signal reflects cross-site scripting and SQL injection weaknesses, which are endemic to web applications handling user input and database queries without sufficient sanitization. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpmarka over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8855CRITICAL The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL inj | Jan 7, 2025 | 9.8 | 27 | NO | NO |
CVE-2024-8857MEDIUM The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Store | Jan 7, 2025 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpmarka.
Media articles that mention a CVE ID that affects a product developed by Wpmarka — matched by CVE ID, not by vendor name.