### [CVE-2021-24835](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24835) ![](https://img.shields.io/static/v1?label=Product&message=WCFM%20%E2%80%93%20Frontend%20Manager%20for%20WooCommerce%20along%20with%20Bookings%20Subscription%20Listings%20Compatible&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=6.5.12%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-89%20SQL%20Injection&color=brightgreen) ### Description The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using it in a SQL statement, allowing low privilege users such as Subscribers to perform SQL injection attacks ### POC #### Reference - https://wpscan.com/vulnerability/c493ac9c-67d1-48a9-be21-824b1a1d56c2 #### Github - https://github.com/20142995/nuclei-templates - https://github.com/ARPSyndicate/cvemon