The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by high privilege users
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-43077 | The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by high privilege users |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-30T15:32:41.083Z
Reserved: 2022-10-27T00:00:00.000Z
Link: CVE-2022-3720
Updated: 2024-08-03T01:20:57.121Z
Status : Modified
Published: 2022-11-21T11:15:20.823
Modified: 2025-04-30T16:15:24.630
Link: CVE-2022-3720
No data.
OpenCVE Enrichment
No data.
EUVD