PT-2025-47430 · WordPress · Wordpress Community Events
CVE-2025-12646
·
Publicado
2025-11-19
·
Atualizado
2025-11-24
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WordPress Community Events plugin versions prior to 1.5.5
Description
The WordPress Community Events plugin is susceptible to SQL Injection due to inadequate input validation and query preparation. Specifically, the
dayofyear parameter is not properly sanitized, allowing attackers to inject malicious SQL code. This could enable unauthorized access to sensitive database information. The vulnerable parameter dayofyear is used in the existing SQL query without sufficient escaping.Recommendations
Update the WordPress Community Events plugin to version 1.5.5 or later.
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wordpress Community Events