CVE-2017-1002026
high
CVSS v3
8.8
CVSS v2
6.5
VIR risk
8.8
Description
Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize user-supplied input via the $id parameter before passing it into an SQL statement.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: larry0@me.com — http://www.vapidlabs.com/advisory.php?v=197
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| eventespresso | event_espresso | 3.1.37.11.l | |
References
CWEs
CWE-89
Verify integrity in audit chain (admin only). AS-IS.