cleantalk
Vulnerabilities and Security Researches

Event Monster – Event Management, Tickets Booking, Upcoming Event, CVE-2022-3720

CVE, Research URL

CVE-2022-3720

Published on
Nov 21, 2022
Research Description
The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by high privilege users
Affected versions
max 1.2.1.
Status
vulnerable