Vulnerabilities > Eventespresso > High

DATE CVE VULNERABILITY TITLE RISK
2017-09-14 CVE-2017-1002026 SQL Injection vulnerability in Eventespresso Event Espresso 3.1.37.11.L
Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize user-supplied input via the $id parameter before passing it into an SQL statement.
network
low complexity
eventespresso CWE-89
8.8