Vulnerability Description
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wclovers | Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible | < 3.4.12 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/763c08a0-4b2b-4487-b91c-be6cc2b9322eExploitThird Party Advisory
- https://wpscan.com/vulnerability/763c08a0-4b2b-4487-b91c-be6cc2b9322eExploitThird Party Advisory
FAQ
What is CVE-2021-24849?
CVE-2021-24849 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before ...
How severe is CVE-2021-24849?
CVE-2021-24849 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-24849?
Check the references section above for vendor advisories and patch information. Affected products include: Wclovers Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible.