Impact
Improper neutralization of special elements in SQL commands allows attackers to perform blind SQL injection against the Liquid Web / StellarWP The Events Calendar plugin. This flaw could enable an attacker to extract sensitive data from the underlying database, compromise site integrity, or possibly retrieve user credentials due to the high severity indicated by CWE‑89.
Affected Systems
The vulnerability affects The Events Calendar plugin versions 6.15.12 through 6.16.2. Users running any of these releases should verify that the plugin is upgraded to 6.16.3 or later.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity even though the EPSS score is below 1%, meaning exploitation is currently low but not impossible. The flaw is not listed in the CISA KEV catalog, but because it is a blind SQL injection it can be exploited remotely if the attacker can send crafted HTTP requests to the plugin’s endpoints. The attack vector is inferred to be a remote or local exploitation via the web interface rather than requiring privileged access.
OpenCVE Enrichment