Event Espresso Free/Lite <= 3.1.37.12.L - Unauthenticated SQL Injection
critical
The Event Espresso Free/Lite plugin for WordPress is vulnerable to Time-Based Blind SQL Injection via the ‘recurrence_id’ parameter in versions up to, and including, 3.1.37.12.L due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possi...
- CVSS:
- 9.8
- Affected:
- up to 3.1.37.12, up to 3.1.37.12.L
- Fixed in:
- 3.1.37.14
- Disclosed:
- Sep 30, 2019
CVE-2017-14760 on NVD →
Event Expresso Free <= 3.1.37.11.L - Authenticated SQL Injection
high
Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize user-supplied input via the $id parameter before passing it into an SQL statement.
- CVSS:
- 8.8
- Affected:
- up to 3.1.37.11.L
- Fixed in:
- 3.1.37.12.L
- Disclosed:
- Jul 4, 2017
CVE-2017-1002026 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database