ZeroHour

CVE-2017-9429

CVSS 3.0
8.8 high
EPSS
3%p85
Published
()
Modified
Description

SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php.

Vendors
event list project
Products
event list
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.