plugin

Simple Events Calendar Vulnerabilities

2 known security issues reported for the Simple Events Calendar WordPress plugin. Most recent disclosed Jul 24, 2021.

2 high

Running Simple Events Calendar on your site? Check whether your installed version is affected.

Scan your site free

Simple Events Calendar <= 1.4.0 - Authenticated SQL Injection

high

The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue

CVSS:
7.2
Affected:
up to 1.4.0
Fixed in:
1.4.1
Disclosed:
Jul 24, 2021

CVE-2021-24552 on NVD →

Simple Events Calendar < 1.3.6 - Authenticated (Admin+) SQL Injection

high

The Simple Events Calendar for WordPress is vulnerable to SQL Injection via the ‘event_id’ parameter in versions before 1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with admin-level priv...

CVSS:
7.2
Affected:
up to 1.3.6
Fixed in:
1.3.6
Disclosed:
Nov 3, 2017

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database