Vulnerabilities (CVE)

Filtered by vendor Wclovers Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24835 1 Wclovers 1 Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible 2021-11-13 6.5 MEDIUM 8.8 HIGH
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using it in a SQL statement, allowing low privilege users such as Subscribers to perform SQL injection attacks