Pricing
Case studies
Login
Start trial
My auctions allegro
wphocus
Developer
3.6.35
Latest version
500
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
2 present
10 patched
6 Mitigation rules
Cross Site Scripting (XSS) vulnerability
<= 3.6.35
05/03/2026
Cross Site Scripting (XSS) vulnerability
<= 3.6.32
19/01/2026
Local File Inclusion vulnerability
<= 3.6.33
04/01/2026
Cross Site Request Forgery (CSRF) vulnerability
<= 3.6.33
17/12/2025
Cross Site Scripting (XSS) vulnerability
<= 3.6.35
17/12/2025
Unauthenticated Local File Inclusion via controller vulnerability
<= 3.6.32
05/12/2025
Unauthenticated SQL Injection via auction_id vulnerability
<= 3.6.32
05/12/2025
Authenticated (Admin+) SQL Injection vulnerability
<= 3.6.31
10/10/2025
Cross Site Request Forgery (CSRF) vulnerability
<= 3.6.33
14/04/2025
SQL Injection vulnerability
<= 3.6.20
31/03/2025
Reflected Cross Site Scripting (XSS) vulnerability
<= 3.6.18
15/01/2025
Reflected Cross-Site Scripting vulnerability
<= 3.6.17
02/12/2024