ZeroHour

CVE-2022-3720

PoC
CVSS 3.1
7.2 high
EPSS
<1%p60
Published
()
Modified
Description

The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by high privilege users

Vendors
awplife
Products
event monster
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.