PT-2025-47430 · WordPress · Wordpress Community Events

Published

2025-11-19

·

Updated

2025-11-24

·

CVE-2025-12646

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress Community Events plugin versions prior to 1.5.5
Description The WordPress Community Events plugin is susceptible to SQL Injection due to inadequate input validation and query preparation. Specifically, the dayofyear parameter is not properly sanitized, allowing attackers to inject malicious SQL code. This could enable unauthorized access to sensitive database information. The vulnerable parameter dayofyear is used in the existing SQL query without sufficient escaping.
Recommendations Update the WordPress Community Events plugin to version 1.5.5 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-12646

Affected Products

Wordpress Community Events