GHSA-xxj4-g6jj-4r95HighCVSS 8.1
The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled...
🔗 CVE IDs covered (1)
📋 Description
The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to other people.