Events Manager <= 7.4.6 - Unauthenticated SQL Injection via 'scope' Parameter
- ID
- WPSEC-2026-0660
- Plugin
- Events Manager – Calendar, Bookings, Tickets, Appointments and more! (events-manager)
- Affected
- from 7.3 before 7.4.7
- Remediation
- Update to 7.4.7 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Weakness
- CWE-89
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
- Attack surface
- Events Manager on WPSec AttackSurface
- Fix released
- Published
Description
The Events Manager plugin for WordPress is vulnerable to SQL Injection via the 'scope' parameter in versions 7.3 up to, and including, 7.4.6. A nested array in the scope 'name' key bypasses the date validation applied to the scope start and end values, which are then concatenated into the event and location search query without escaping or preparation. The parameter is accepted by the plugin's REST API searches, which require a logged-in user of any role, and by its read-only 'list-events' and 'list-locations' abilities, which are registered without a permission check and exposed through the WordPress Abilities REST API on WordPress 6.9 and later. This makes it possible for unauthenticated attackers on sites running WordPress 6.9 or later, and for authenticated attackers with Subscriber-level access or above on older WordPress versions, to append additional SQL to existing queries and extract sensitive information from the database.
References
- https://wpsec.com/vuln/WPSEC-2026-0660/
- https://plugins.svn.wordpress.org/events-manager/tags/7.4.7/
- https://wordpress.org/plugins/events-manager/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS