CVE-2021-24849 Information
Jun 07, 2022
cve
Description
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12 available to unauthenticated and authenticated user does not properly sanitise multiple parameters before using them in SQL statements leading to SQL injections
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://wpscan.com/vulnerability/763c08a0-4b2b-4487-b91c-be6cc2b9322e
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: