Логотип exploitDog
bind:CVE-2021-24849
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24849

Количество 2

Количество 2

nvd логотип

CVE-2021-24849

больше 3 лет назад

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2hw2-7jq8-w9vp

больше 3 лет назад

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24849

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

CVSS3: 9.8
70%
Средний
больше 3 лет назад
github логотип
GHSA-2hw2-7jq8-w9vp

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

70%
Средний
больше 3 лет назад

Уязвимостей на страницу