CVE-2020-35012: Events Manager < 5.9.8 - Admin+ SQL Injection
Published Dec 1, 2021
·Updated
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
Affected Software
2 affected components
Pixelite Events Manager Wordpress<5.9.8
Wp-events-plugin Events Manager Wordpress<5.9.8
Remediation
Event History
Dec 1, 2021
CVE Published
via MITRE·10:50 PM
Data Sourced
via MITRE·10:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-35012.
2
What is the severity of CVE-2020-35012?
The severity of CVE-2020-35012 is high.
3
Which WordPress plugin is affected by this vulnerability?
The Events Manager WordPress plugin is affected by this vulnerability.
4
What is the version range of the affected plugin?
The affected version range of the Events Manager WordPress plugin is up to and excluding 5.9.8.
5
What is the CWE ID of CVE-2020-35012?
The CWE ID of CVE-2020-35012 is 89.