WordPress security by component
WCFM Frontend Manager
Plugin description
WCFM Frontend Manager is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Apr 05, 2023; the highest CVE/CNA score is 9.8.
Plugin slug:
frontend-manager-for-woocommerce-along-with-bookings-subscription-listings-compaLatest vulnerability
CVE-2022-4938: WCFM Frontend Manager: Cross-site request forgery
WCFM Frontend Manager is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
| Safe version |
|
||
|---|---|---|---|
| Apr 05, 2023 |
CVE-2022-4938
WCFM Frontend Manager: Cross-site request forgery
WCFM Frontend Manager is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.3
NVD8.8
|
| Apr 05, 2023 |
CVE-2022-4937
WCFM Frontend Manager: A security weakness
WCFM Frontend Manager is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVD8.8
|
| Dec 21, 2021 |
CVE-2021-24849
wcfm_ajax_controller AJAX action of the WCFM Marketplace: SQL injection
wcfm_ajax_controller AJAX action of the WCFM Marketplace is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Nov 08, 2021 |
CVE-2021-24835
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible: SQL injection
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD8.8
|