Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-24849

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections
Exploit prediction scoring system (EPSS) score
EPSS Score 0.699
EPSS Ranking 98.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-24849


Contact Us

Shodan ® - All rights reserved