← WordPress Vulnerabilities
WordPress security by component

request_list_request AJAX call of the Car Seller - Auto Classifieds Script

request_list_request AJAX call of the Car Seller - Auto Classifieds Script provides an AJAX request action for listing requests in a car classifieds system.

request_list_request AJAX call of the Car Seller - Auto Classifieds Script (cars-seller-auto-classifieds-script) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published May 14, 2021; the highest published CVSS base score is 9.8.

Plugin slug: cars-seller-auto-classifieds-script

CVE-2021-24285: request_list_request AJAX call of the Car Seller - Auto Classifieds Script: SQL injection

request_list_request AJAX call of the Car Seller - Auto Classifieds Script is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.

PublishedMay 14, 2021
Safe version guidanceSee mitigation notes
Published vulnerabilities for cars-seller-auto-classifieds-script
Safe version
May 14, 2021 CVE-2021-24285
request_list_request AJAX call of the Car Seller - Auto Classifieds Script: SQL injection
request_list_request AJAX call of the Car Seller - Auto Classifieds Script is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD9.8