Browse all 3 CVE security advisories affecting WP Marka. AI-powered Chinese analysis, POCs, and references for each vulnerability.
WP Marka is a WordPress plugin designed for brand management and marketing automation. Historically, it has been vulnerable to multiple security issues including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. The plugin's three recorded CVEs highlight consistent security flaws in input validation and access control. While no major public security incidents have been documented, the pattern of vulnerabilities suggests potential risks for sites that fail to maintain timely updates. Organizations using WP Marka should prioritize security patches and implement additional hardening measures to mitigate the risk of exploitation.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-22349 | WordPress WordPress Auction Plugin plugin <= 3.7 - SQL Injection vulnerability — WordPress Auction PluginCWE-89 | 7.6 | High | 2025-01-07 |
| CVE-2024-54207 | WordPress WordPress Auction Plugin plugin <= 3.7 - Cross Site Scripting (XSS) vulnerability — WordPress Auction PluginCWE-79 | 5.9 | Medium | 2024-12-06 |
| CVE-2024-51615 | WordPress WordPress Auction Plugin plugin <= 3.7 - SQL Injection vulnerability — WordPress Auction PluginCWE-89 | 9.3 | Critical | 2024-12-06 |
This page lists every published CVE security advisory associated with WP Marka. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.