Skip to content

Known CVE

WCFM WooCommerce Multivendor Marketplace < 3.4.12 - SQL Injection

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections.

CVE-2021-24849

Critical2021CVSS 9.8CWE-89

time-based-sqli · wpscan · cve2021 · wp · wp-plugin · wordpress · wc-multivendor-marketplace · sqli

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website