plugin

Event Espresso Free Vulnerabilities

2 known security issues reported for the Event Espresso Free WordPress plugin. Most recent disclosed Sep 30, 2019.

1 critical 1 high

Running Event Espresso Free on your site? Check whether your installed version is affected.

Scan your site free

Event Espresso Free/Lite <= 3.1.37.12.L - Unauthenticated SQL Injection

critical

The Event Espresso Free/Lite plugin for WordPress is vulnerable to Time-Based Blind SQL Injection via the ‘recurrence_id’ parameter in versions up to, and including, 3.1.37.12.L due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possi...

CVSS:
9.8
Affected:
up to 3.1.37.12, up to 3.1.37.12.L
Fixed in:
3.1.37.14
Disclosed:
Sep 30, 2019

CVE-2017-14760 on NVD →

Event Expresso Free <= 3.1.37.11.L - Authenticated SQL Injection

high

Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize user-supplied input via the $id parameter before passing it into an SQL statement.

CVSS:
8.8
Affected:
up to 3.1.37.11.L
Fixed in:
3.1.37.12.L
Disclosed:
Jul 4, 2017

CVE-2017-1002026 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database