S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Feb 18, 2024

CVE-2021-24849 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in WCFM WooCommerce Multivendor Marketplace plugin for WordPress affects v. before 3.4.12.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24849
9.8
CVSS

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WCFM Marketplace – Best Multivendor Marketplace for WooCommerce
AFFECTED< 3.4.12SAFE ✓≥ 3.4.12
Updated Aug 21, 2026View on NVD →
Detail

Vulnerability Overview:

  • CVE Identifier: CVE-2021-24849
  • Vulnerable Component: WCFM WooCommerce Multivendor Marketplace plugin
  • Parameters Affected: Multiple parameters in the wcfm_ajax_controller AJAX action
  • Issue: Insufficient sanitization leading to SQL Injection

Vulnerability Details:

The vulnerability arises from the plugin's failure to adequately sanitize user-supplied input before using it in SQL queries. This oversight makes it possible for attackers to manipulate SQL queries by injecting malicious SQL code through the plugin’s AJAX action wcfm_ajax_controller. The affected parameters include transaction_id, among others, which can be exploited by both unauthenticated and authenticated users.

Possible Effects:

Exploiting this vulnerability could allow attackers to gain unauthorized access to the database, retrieve sensitive information, modify database entries, and potentially compromise the WordPress site. This could lead to data breaches, identity theft, and unauthorized administrative operations.

Why Choose S4E:

S4E (S4E) provides comprehensive vulnerability scanning solutions tailored to your security needs. By choosing S4E, you benefit from:

  • Continuous Monitoring: Stay ahead of threats with real-time alerts and updates.
  • Expert Support: Gain access to cybersecurity experts for guidance on vulnerability mitigation.
  • Customizable Scans: Tailor scans to fit the specific needs of your organization, ensuring thorough coverage and protection.

References:

Solution Advice
  • Immediate Action: Upgrade to version 3.4.12 or later of the WCFM WooCommerce Multivendor Marketplace plugin.
  • Verify Updates: Ensure that the plugin is updated to the latest version available from the vendor.
  • Review Logs: Check web and database logs for unusual or unauthorized queries indicating potential exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24849 scanner - SQL Injection (SQLi) vulnerability in WCFM WooCommerce Multivendor Marketplace plugin for WordPress S4E