CVE-2014-8586

CP Multi View Event Calendar 1.01 - SQL Injection via calid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-8586. PoCs published by Claudio Viviani, Joaquin Ramirez Martinez, bperry, including Metasploit module auxiliary/scanner/http/wordpress_cp_calendar_sqli.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in CP Multi View Event Calendar 1.01 via the 'calid' parameter. It includes payloads for boolean-based blind, error-based, UNION query, and time-based blind SQL injection techniques.

Description

SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter.

Exploits (2)

exploitdb WORKING POC
by Claudio Viviani · textwebappsphp
https://www.exploit-db.com/exploits/35073

This exploit demonstrates a SQL injection vulnerability in CP Multi View Event Calendar 1.01 via the 'calid' parameter. It includes payloads for boolean-based blind, error-based, UNION query, and time-based blind SQL injection techniques.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: CP Multi View Event Calendar 1.01
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit SCANNER
by Joaquin Ramirez Martinez, bperry · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/wordpress_cp_calendar_sqli.rb

This Metasploit module scans for an unauthenticated SQL injection vulnerability in the WordPress CP Multi-View Calendar plugin v1.1.4. It uses a UNION-based SQLi technique to detect the vulnerability by injecting a payload into the 'id' parameter.

Classification
Scanner 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WordPress CP Multi-View Calendar plugin v1.1.4
No auth needed
Prerequisites: Target must have the vulnerable plugin installed and accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70718
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/97766
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/113670
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35073

Scores

EPSS 0.4107
EPSS Percentile 98.5%

Details

CWE
CWE-89
Status published
Products (1)
cp_multi_view_event_calendar_project/cp_multi_view_event_calendar 1.0.1
Published Nov 04, 2014
Tracked Since Feb 18, 2026