vendor:
Events Calendar
by:
Dennis Veninga
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Events Calendar
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: YES
Related CWE: CVE-2018-5315
CPE: a:wachipi:events_calendar:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WordPress
2018
Wichipi Events Calendar – SQL Injection
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. To exploit, union select 29 columns. User can use 2 or 25 for information gathering.
Mitigation:
Vendor reply & fix 09-01-2018