CVE-2017-1002018

CRITICAL

WordPress Plugin Eventr <1.02.2 - SQL Injection

Title source: llm
STIX 2.1

Description

Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and attendees.php code do not sanitize input, this allows for blind SQL injection via the event parameter.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://wordpress.org/plugins/eventr/
Exploit, Third Party Advisory x_refsource_misc
http://www.vapidlabs.com/advisory.php?v=192

Scores

CVSS v3 9.8
EPSS 0.0248
EPSS Percentile 82.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
Binny V A/eventr unspecified - 1.02.2
eventr_project/eventr 1.02.2
Published Sep 14, 2017
Tracked Since Feb 18, 2026