Impact
The vulnerability is a lack of sanitization for a user‑controlled value that is used directly in a SQL statement in the Events Manager WordPress plugin, exposing it to SQL injection. An attacker with a subscriber role or higher can forge database queries to modify or delete booking consent records that belong to other users, compromising data integrity and potentially enabling further exploitation. This flaw is a classic UTF‑8 injection mistake.
Affected Systems
The flaw exists in all installations of the Events Manager plugin version 7.4.0 and earlier, regardless of hosting environment, as the code paths are identical. Vendors are not listed in the CVE, but affected sites run WordPress with the plugin. No specific version sub‑range beyond 7.4.1 is mentioned.
Risk and Exploitability
Although no CVSS or EPSS score is publicly available, the attack vector is remote via web requests and can be performed from any authenticated subscriber account, which is a non‑privileged role. The lack of a defensive patch and the high impact of data tampering mean the risk is considerable. The vulnerability is not listed in CISA KEV, but should still be treated with urgency.
OpenCVE Enrichment