GHSA-xxj4-g6jj-4r95HighCVSS 8.1

The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled...

Published
August 12, 2026
Last Modified
August 12, 2026

🔗 CVE IDs covered (1)

📋 Description

The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to other people.

🔗 References (3)