ZeroHour

CVE-2021-24849

PoC
CVSS 3.1
9.8 critical
EPSS
8%p95
Published
()
Modified
Description

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

Vendors
wclovers
Products
frontend manager for woocommerce along with bookings subscription listings compatible
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.