Eventify™ – Simple Events [eventify] <= 2.1 (unfixed + closed)
unknown
[en] The Eventify™ WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 2.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 26, 2022
CVE-2022-4110 on NVD →
Eventify <= 2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Eventify plugin for WordPress is vulnerable to Stored Cross-Site Scripting parameter in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts...
- CVSS:
- 5.5
- Affected:
- up to 2.1
- Fix:
- No patched version reported
- Disclosed:
- Nov 30, 2022
CVE-2022-4110 on NVD →
Eventify - Simple Events <= 1.7.f - SQL Injection via eventid
high
The Eventify - Simple Events plugin for WordPress is vulnerable to SQL Injection via the ‘eventid’ parameter in versions up to, and including, 1.7.f due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attack...
- CVSS:
- 8.1
- Affected:
- up to 1.7.f
- Fixed in:
- 1.7.g
- Disclosed:
- Sep 7, 2011
Eventify™ – Simple Events [eventify] < 1.8 (closed)
unknown
WordPress Eventify plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Upgrade the plugin.
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- Sep 7, 2011
Eventify™ – Simple Events [eventify] < 1.7.g (closed)
unknown
The Eventify - Simple Events plugin for WordPress is vulnerable to SQL Injection via the ‘eventid’ parameter in versions up to, and including, 1.7.f due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attack...
- Affected:
- up to 1.7.g
- Fixed in:
- 1.7.g
- Disclosed:
- Sep 7, 2011
Eventify™ – Simple Events [eventify] <= 1.7.f (unfixed + closed)
unknown
The Eventify™ – Simple Events WordPress plugin was affected by a Simple Events <= 1.7.f - SQL Injection security vulnerability.
- Affected:
- up to 1.7.f
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database