PT-2025-41329 · WordPress · Wordpress Community Events

Ifoundbug

·

Published

2025-10-09

·

Updated

2025-11-08

·

CVE-2025-10586

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress Community Events plugin versions through 1.5.1
Description The WordPress Community Events plugin is susceptible to a SQL Injection issue due to inadequate input sanitization of the event venue parameter. This allows authenticated attackers with Subscriber-level access or higher to inject additional SQL queries into existing database queries, potentially leading to the extraction of sensitive information. The event venue parameter is vulnerable because of insufficient escaping and a lack of proper preparation of the SQL query.
Recommendations Versions prior to and including 1.5.1 should be updated.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10586

Affected Products

Wordpress Community Events