Record summary

CVE-2021-24849 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

WCFM Marketplace – Best Multivendor Marketplace for WooCommerce

CVE List3.4.12 to < 3.4.12affected

Nuclei templates

1
ProjectDiscoveryCRITICALWCFM WooCommerce Multivendor Marketplace < 3.4.12 - SQL InjectionCVSS 9.8

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections.

Impact

Unauthenticated attackers can execute SQL injection through multiple unsanitized parameters, potentially gaining access to all WooCommerce marketplace data including customer and vendor information.

Remediation

Fixed in 3.4.12

WeaknessesCWE-89
Authorsritikchaddha
Template tagstime-based-sqliwpscancvecve2021wpwp-pluginwordpresswc-multivendor-marketplacesqliwcloversvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:wclovers:frontend_manager_for_woocommerce_along_with_bookings_subscription_listings_compatible:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/wc-multivendor-marketplace
FOFA: body=/wp-content/plugins/wc-multivendor-marketplace

Source: ProjectDiscovery

References

2