plugin

Eventify Vulnerabilities

6 known security issues reported for the Eventify WordPress plugin. Most recent disclosed Dec 26, 2022.

1 high 1 medium

Running Eventify on your site? Check whether your installed version is affected.

Scan your site free

Eventify&trade; &#8211; Simple Events [eventify] <= 2.1 (unfixed + closed)

unknown

[en] The Eventify™ WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 2.1
Fix:
No patched version reported
Disclosed:
Dec 26, 2022

CVE-2022-4110 on NVD →

Eventify <= 2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Eventify plugin for WordPress is vulnerable to Stored Cross-Site Scripting parameter in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts...

CVSS:
5.5
Affected:
up to 2.1
Fix:
No patched version reported
Disclosed:
Nov 30, 2022

CVE-2022-4110 on NVD →

Eventify - Simple Events <= 1.7.f - SQL Injection via eventid

high

The Eventify - Simple Events plugin for WordPress is vulnerable to SQL Injection via the ‘eventid’ parameter in versions up to, and including, 1.7.f due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attack...

CVSS:
8.1
Affected:
up to 1.7.f
Fixed in:
1.7.g
Disclosed:
Sep 7, 2011

Eventify&trade; &#8211; Simple Events [eventify] < 1.8 (closed)

unknown

WordPress Eventify plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Sep 7, 2011

Eventify&trade; &#8211; Simple Events [eventify] < 1.7.g (closed)

unknown

The Eventify - Simple Events plugin for WordPress is vulnerable to SQL Injection via the ‘eventid’ parameter in versions up to, and including, 1.7.f due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attack...

Affected:
up to 1.7.g
Fixed in:
1.7.g
Disclosed:
Sep 7, 2011

Eventify&trade; &#8211; Simple Events [eventify] <= 1.7.f (unfixed + closed)

unknown

The Eventify&trade; &ndash; Simple Events WordPress plugin was affected by a Simple Events &lt;= 1.7.f - SQL Injection security vulnerability.

Affected:
up to 1.7.f
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database