CVE-2017-9429

HIGH

WordPress Event List <0.7.8 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-9429. PoCs published by Dimitrios Tsagkarakis.

AI-analyzed exploit summary This is a writeup describing a blind SQL injection vulnerability in the WordPress Event List plugin (version <= 0.7.8). The PoC demonstrates a time-based SQLi via the 'id' parameter in an authenticated admin context.

Description

SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php.

Exploits (1)

exploitdb WRITEUP
by Dimitrios Tsagkarakis · textwebappsphp
https://www.exploit-db.com/exploits/42173

This is a writeup describing a blind SQL injection vulnerability in the WordPress Event List plugin (version <= 0.7.8). The PoC demonstrates a time-based SQLi via the 'id' parameter in an authenticated admin context.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin Event List <= 0.7.8
Auth required
Prerequisites: Authenticated WordPress user access · Event List plugin version <= 0.7.8 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42173/

Scores

CVSS v3 8.8
EPSS 0.0273
EPSS Percentile 84.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
event_list_project/event_list 0.7.8
Published Jun 13, 2017
Tracked Since Feb 18, 2026