vendor:
Eventify - Simple Events plugin
by:
Miroslav Stampar
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Eventify - Simple Events plugin
Affected Version From: 1.7.f
Affected Version To: 1.7.f
Patch Exists: No
Related CWE:
CPE: a:wordpress:eventify_plugin
Platforms Tested:
2011
WordPress Eventify – Simple Events plugin <= 1.7.f SQL Injection Vulnerability
The WordPress Eventify - Simple Events plugin version 1.7.f and below is vulnerable to SQL Injection. By sending a specially crafted POST request to the fetcheventdetails.php file, an attacker can execute arbitrary SQL queries on the database.
Mitigation:
Update to the latest version of the plugin or apply a patch if available. Enable magic_quotes to prevent SQL Injection attacks.