Impact
A subscriber SQL Injection vulnerability exists in the WordPress Events Manager plugin versions 7.4.6 and earlier. The flaw allows an attacker to inject arbitrary SQL into a subscriber-related request, potentially exposing or modifying event data stored in the database. The weakness is classified under CWE-89, indicating unsanitized input handling during SQL query construction.
Affected Systems
WordPress sites running the Events Manager plugin through version 7.4.6 included. The vulnerability is present in all installations of Marcus:Events Manager up to that release, regardless of the specific WordPress version, as the plugin itself contains the vulnerable code.
Risk and Exploitability
With a CVSS score of 8.5, this vulnerability is considered high severity. The EPSS score is currently unavailable, so the likelihood of exploitation cannot be quantified, but the feature exposes the plugin to uncontrolled data input, which attackers can leverage to execute arbitrary queries. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented exploits yet. The likely attack vector is through the subscriber interface, possibly via form submissions or API calls that pass unsanitized parameters. Expertise in SQL injection is required to exploit effectively.
OpenCVE Enrichment