Critical severity9.8NVD Advisory· Published Dec 21, 2021· Updated Jun 17, 2026
CVE-2021-24849
CVE-2021-24849
Description
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:wclovers:frontend_manager_for_woocommerce_along_with_bookings_subscription_listings_compatible:*:*:*:*:*:wordpress:*:*Range: <3.4.12
- WordPress/WCFM Marketplacedescription
- Range: <3.4.12
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/763c08a0-4b2b-4487-b91c-be6cc2b9322envdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.