PT-2025-47430 · WordPress · Wordpress Community Events

CVE-2025-12646

·

Published

2025-11-19

·

Updated

2025-11-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress Community Events plugin versions prior to 1.5.5
Description The WordPress Community Events plugin is susceptible to SQL Injection due to inadequate input validation and query preparation. Specifically, the dayofyear parameter is not properly sanitized, allowing attackers to inject malicious SQL code. This could enable unauthorized access to sensitive database information. The vulnerable parameter dayofyear is used in the existing SQL query without sufficient escaping.
Recommendations Update the WordPress Community Events plugin to version 1.5.5 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12646

Affected Products

Wordpress Community Events