CVE-2017-14760: SQL Injection
Published Sep 27, 2017
·Updated
SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrenceid parameter to /wp-admin/admin.php.
Affected Software
1 affected component
Eventespresso Event Espresso Lite Wordpress<=3.1.37.12.l
Event History
Sep 27, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14760?
CVE-2017-14760 has a medium severity rating due to the potential for SQL injection exploits.
2
How do I fix CVE-2017-14760?
To fix CVE-2017-14760, update the Event Espresso Lite plugin to a version later than 3.1.37.12.L.
3
What specific vulnerability does CVE-2017-14760 address?
CVE-2017-14760 addresses an SQL injection vulnerability in the Event Espresso Lite plugin for WordPress.
4
Which plugin is affected by CVE-2017-14760?
CVE-2017-14760 affects the Event Espresso Lite plugin (version 3.1.37.12.L) for WordPress.
5
Is there any known exploit for CVE-2017-14760?
Yes, there are reports of exploit attempts leveraging the SQL injection vulnerability in CVE-2017-14760.