PT-2025-47430 · WordPress · Wordpress Community Events

CVE-2025-12646

·

Publicado

2025-11-19

·

Atualizado

2025-11-24

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress Community Events plugin versions prior to 1.5.5
Description The WordPress Community Events plugin is susceptible to SQL Injection due to inadequate input validation and query preparation. Specifically, the dayofyear parameter is not properly sanitized, allowing attackers to inject malicious SQL code. This could enable unauthorized access to sensitive database information. The vulnerable parameter dayofyear is used in the existing SQL query without sufficient escaping.
Recommendations Update the WordPress Community Events plugin to version 1.5.5 or later.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-12646

Produtos afetados

Wordpress Community Events