Impact
The flaw in Events Manager before version 7.4.1 allows a user with a subscriber role or higher to inject arbitrary SQL through a lack of input sanitisation. An attacker can therefore modify or delete booking consent records that belong to other users, compromising data integrity and potentially revealing sensitive booking information.
Affected Systems
All WordPress sites running the Events Manager plugin with a version earlier than 7.4.1 are vulnerable. The vulnerability exists regardless of the hosting environment or other installed plugins, as the code paths are identical across all affected releases.
Risk and Exploitability
The CVSS score of 8.1 flags this as a high‑severity vulnerability. The attack vector is remote: any authenticated subscriber can trigger the injection via normal web requests. EPSS indicates a probability of exploitation below 1%, and the issue is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread attacks. Nevertheless, the potential impact on user data integrity is significant, warranting prompt remediation.
OpenCVE Enrichment