# Events Manager <= 7.4.6 - Unauthenticated SQL Injection via 'scope' Parameter

- **ID:** WPSEC-2026-0660
- **Plugin:** Events Manager – Calendar, Bookings, Tickets, Appointments and more! (`events-manager`), https://wordpress.org/plugins/events-manager/
- **Affected versions:** from 7.3 before 7.4.7
- **Fixed in:** 7.4.7 (Update to 7.4.7 or later.)
- **Severity:** High 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **Weakness:** CWE-89
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/events-manager
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0660/

## Description

The Events Manager plugin for WordPress is vulnerable to SQL Injection via the 'scope' parameter in versions 7.3 up to, and including, 7.4.6. A nested array in the scope 'name' key bypasses the date validation applied to the scope start and end values, which are then concatenated into the event and location search query without escaping or preparation. The parameter is accepted by the plugin's REST API searches, which require a logged-in user of any role, and by its read-only 'list-events' and 'list-locations' abilities, which are registered without a permission check and exposed through the WordPress Abilities REST API on WordPress 6.9 and later. This makes it possible for unauthenticated attackers on sites running WordPress 6.9 or later, and for authenticated attackers with Subscriber-level access or above on older WordPress versions, to append additional SQL to existing queries and extract sensitive information from the database.

## References

- https://wpsec.com/vuln/WPSEC-2026-0660/
- https://plugins.svn.wordpress.org/events-manager/tags/7.4.7/
- https://wordpress.org/plugins/events-manager/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0660/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
