First published: Tue Nov 04 2014(Updated: )
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople CP Multi View Event Calendar | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8586 has a high severity rating due to its ability to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2014-8586, update the CP Multi View Event Calendar plugin to the latest version that addresses this vulnerability.
Any WordPress installations using the CP Multi View Event Calendar plugin version 1.0.1 are affected by CVE-2014-8586.
CVE-2014-8586 is classified as an SQL injection vulnerability.
Yes, CVE-2014-8586 can be exploited remotely by attackers through the calid parameter.