Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxj4-g6jj-4r95

Опубликовано: 12 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to other people.

The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to other people.

EPSS

Процентиль: 13%
0.00221
Низкий

8.1 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.1
nvd
7 дней назад

The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to other people.

EPSS

Процентиль: 13%
0.00221
Низкий

8.1 High

CVSS3

Дефекты

CWE-89