Vulnerabilities / Events Manager / WPSEC-2026-0660

Events Manager <= 7.4.6 - Unauthenticated SQL Injection via 'scope' Parameter

High 7.5 CWE-89Fixed in 7.4.7
ID
WPSEC-2026-0660
Plugin
Events Manager – Calendar, Bookings, Tickets, Appointments and more! (events-manager)
Affected
from 7.3 before 7.4.7
Remediation
Update to 7.4.7 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness
CWE-89
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
Attack surface
Events Manager on WPSec AttackSurface
Fix released
Published

Description

The Events Manager plugin for WordPress is vulnerable to SQL Injection via the 'scope' parameter in versions 7.3 up to, and including, 7.4.6. A nested array in the scope 'name' key bypasses the date validation applied to the scope start and end values, which are then concatenated into the event and location search query without escaping or preparation. The parameter is accepted by the plugin's REST API searches, which require a logged-in user of any role, and by its read-only 'list-events' and 'list-locations' abilities, which are registered without a permission check and exposed through the WordPress Abilities REST API on WordPress 6.9 and later. This makes it possible for unauthenticated attackers on sites running WordPress 6.9 or later, and for authenticated attackers with Subscriber-level access or above on older WordPress versions, to append additional SQL to existing queries and extract sensitive information from the database.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0