Events Made Easy < 2.2.81 - Unauthenticated SQLi
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 37%
exploitation probability
37%top 2% of all CVEs
observed exploitation
nono source reports it
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
Affected products
Unknown · Events Made Easy