Simple Events Calendar <= 1.4.0 - Authenticated SQL Injection
high
The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue
- CVSS:
- 7.2
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.1
- Disclosed:
- Jul 24, 2021
CVE-2021-24552 on NVD →
Simple Events Calendar < 1.3.6 - Authenticated (Admin+) SQL Injection
high
The Simple Events Calendar for WordPress is vulnerable to SQL Injection via the ‘event_id’ parameter in versions before 1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with admin-level priv...
- CVSS:
- 7.2
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Nov 3, 2017
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database